Three beds deliver the secrets they copy from the catalogue as files (issue 073)
This commit is contained in:
@@ -220,14 +220,13 @@ test("the mesh assigns mongodb, unifi, marrytts and postgres to one node in one
|
||||
{ id: "mesh-state", type: "directory", path: "/var/lib/mesh/mongodb", mode: "0700" },
|
||||
{ id: "state", type: "directory", path: "/var/lib/mongodb", mode: "0700" },
|
||||
{ id: "grants", type: "directory", path: "/var/lib/mongodb/grants", mode: "0700" },
|
||||
{ id: "root-env", type: "file", path: "/var/lib/mongodb/root.env", mode: "0600", content: "MONGO_INITDB_ROOT_PASSWORD=${secret:root}\n" },
|
||||
{ id: "data", type: "directory", path: "/services/mongodb/db-data", mode: "0700" },
|
||||
{ id: "net", type: "network", name: "mongodb" },
|
||||
{
|
||||
id: "server", type: "container", name: "mongo", image: pinned("mongo"), network: "mongodb",
|
||||
env: { MONGO_INITDB_ROOT_USERNAME: "root" },
|
||||
"env-file": ["/var/lib/mongodb/root.env"],
|
||||
volumes: ["/services/mongodb/db-data:/data/db"],
|
||||
// The root password reaches mongo as a file (novox/hq ADR 0086), the shape the catalogue's manifest has.
|
||||
env: { MONGO_INITDB_ROOT_USERNAME: "root", MONGO_INITDB_ROOT_PASSWORD_FILE: "/run/secrets/root" },
|
||||
volumes: ["/services/mongodb/db-data:/data/db", "/var/lib/mongodb/root.secret:/run/secrets/root:ro"],
|
||||
},
|
||||
{
|
||||
id: "runtime", type: "container", name: "mesh-mongodb", image: pinned("mesh-runtime-mongodb"),
|
||||
|
||||
Reference in New Issue
Block a user