From 97d71503ee10dde63a28c657dc1ebcb41aafe397 Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 21 Sep 2026 12:32:00 +0200 Subject: [PATCH] Three beds deliver the secrets they copy from the catalogue as files (issue 073) --- test/integration/assigned-catalogue-apps.test.ts | 7 +++---- test/integration/assigned-catalogue-small.test.ts | 6 ++++-- test/integration/assigned-model-usage.test.ts | 10 ++++++---- 3 files changed, 13 insertions(+), 10 deletions(-) diff --git a/test/integration/assigned-catalogue-apps.test.ts b/test/integration/assigned-catalogue-apps.test.ts index d163449..fd62e0e 100644 --- a/test/integration/assigned-catalogue-apps.test.ts +++ b/test/integration/assigned-catalogue-apps.test.ts @@ -220,14 +220,13 @@ test("the mesh assigns mongodb, unifi, marrytts and postgres to one node in one { id: "mesh-state", type: "directory", path: "/var/lib/mesh/mongodb", mode: "0700" }, { id: "state", type: "directory", path: "/var/lib/mongodb", mode: "0700" }, { id: "grants", type: "directory", path: "/var/lib/mongodb/grants", mode: "0700" }, - { id: "root-env", type: "file", path: "/var/lib/mongodb/root.env", mode: "0600", content: "MONGO_INITDB_ROOT_PASSWORD=${secret:root}\n" }, { id: "data", type: "directory", path: "/services/mongodb/db-data", mode: "0700" }, { id: "net", type: "network", name: "mongodb" }, { id: "server", type: "container", name: "mongo", image: pinned("mongo"), network: "mongodb", - env: { MONGO_INITDB_ROOT_USERNAME: "root" }, - "env-file": ["/var/lib/mongodb/root.env"], - volumes: ["/services/mongodb/db-data:/data/db"], + // The root password reaches mongo as a file (novox/hq ADR 0086), the shape the catalogue's manifest has. + env: { MONGO_INITDB_ROOT_USERNAME: "root", MONGO_INITDB_ROOT_PASSWORD_FILE: "/run/secrets/root" }, + volumes: ["/services/mongodb/db-data:/data/db", "/var/lib/mongodb/root.secret:/run/secrets/root:ro"], }, { id: "runtime", type: "container", name: "mesh-mongodb", image: pinned("mesh-runtime-mongodb"), diff --git a/test/integration/assigned-catalogue-small.test.ts b/test/integration/assigned-catalogue-small.test.ts index 819b711..a977a75 100644 --- a/test/integration/assigned-catalogue-small.test.ts +++ b/test/integration/assigned-catalogue-small.test.ts @@ -229,14 +229,16 @@ test("the mesh assigns postgres, redis, minio and plex to one node in one push, { id: "mesh-state", type: "directory", path: "/var/lib/mesh/minio", mode: "0700" }, { id: "state", type: "directory", path: "/var/lib/minio", mode: "0700" }, { id: "grants", type: "directory", path: "/var/lib/minio/grants", mode: "0700" }, - { id: "root-env", type: "file", path: "/var/lib/minio/root.env", mode: "0600", content: "MINIO_ROOT_USER=meshroot\nMINIO_ROOT_PASSWORD=${secret:root}\n" }, + // The root password reaches minio as a file (novox/hq ADR 0086), the shape the catalogue's manifest has. + { id: "root-env", type: "file", path: "/var/lib/minio/root.env", mode: "0600", content: "MINIO_ROOT_USER=meshroot\n" }, { id: "data", type: "directory", path: "/services/minio/data/data1-1", mode: "0700" }, { id: "net", type: "network", name: "minio" }, { id: "server", type: "container", name: "minio", image: pinned("minio/minio"), network: "minio", args: ["server", "/data", "--console-address", ":9001"], "env-file": ["/var/lib/minio/root.env"], - volumes: ["/services/minio/data/data1-1:/data"], + env: { MINIO_ROOT_PASSWORD_FILE: "/run/secrets/root" }, + volumes: ["/services/minio/data/data1-1:/data", "/var/lib/minio/root.secret:/run/secrets/root:ro"], }, { id: "runtime", type: "container", name: "mesh-minio", image: pinned("mesh-runtime-minio"), diff --git a/test/integration/assigned-model-usage.test.ts b/test/integration/assigned-model-usage.test.ts index c809e63..9928511 100644 --- a/test/integration/assigned-model-usage.test.ts +++ b/test/integration/assigned-model-usage.test.ts @@ -249,10 +249,12 @@ test("usage events are upserted into model-usage's store — latest-per-key, bot resources: [ { id: "mesh-state", type: "directory", path: "/var/lib/mesh/model-usage", mode: "0700" }, { id: "state", type: "directory", path: "/var/lib/model-usage", mode: "0700" }, + // The connection string carries the password, so it reaches the runtime as a file the mesh + // templates (novox/hq ADR 0086), the shape the catalogue's manifest has. { - id: "db-env", type: "file", path: "/var/lib/model-usage/db.env", mode: "0600", + id: "database-url", type: "file", path: "/var/lib/model-usage/database.url", mode: "0600", content: - "DATABASE_URL=postgresql://${bound:postgres-database:as}:${secret:postgres-database}@" + + "postgresql://${bound:postgres-database:as}:${secret:postgres-database}@" + "${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\n", }, { @@ -261,9 +263,9 @@ test("usage events are upserted into model-usage's store — latest-per-key, bot volumes: [ "/var/lib/mesh/model-usage/broker:/run/secrets/broker:ro", "/var/lib/model-usage:/run/state", + "/var/lib/model-usage/database.url:/run/secrets/database-url:ro", ], - env: { MESH_BROKER_FILE: "/run/secrets/broker" }, - "env-file": ["/var/lib/model-usage/db.env"], + env: { MESH_BROKER_FILE: "/run/secrets/broker", DATABASE_URL_FILE: "/run/secrets/database-url" }, }, ], });