The apps bed's mongodb names its secrets' owner, as the catalogue's does, and says what the server said when the consumer cannot reach it

This commit is contained in:
2026-09-21 13:43:42 +02:00
parent e085e31f95
commit b0e7cf96d1
@@ -215,6 +215,8 @@ test("the mesh assigns mongodb, unifi, marrytts and postgres to one node in one
receives: { "mongodb-database": "/var/lib/mongodb/grants/mesh.json" },
grants: { "mongodb-database": "/var/lib/mongodb/grants" },
"own-secrets": { root: "/var/lib/mongodb/root.secret", broker: "/var/lib/mesh/mongodb/broker" },
// The image drops to its own user before it reads the password file (ADR 0086; as the catalogue's).
"secrets-owner": "999:999",
resources: [
{ id: "mesh-state", type: "directory", path: "/var/lib/mesh/mongodb", mode: "0700" },
{ id: "state", type: "directory", path: "/var/lib/mongodb", mode: "0700" },
@@ -413,7 +415,9 @@ test("the mesh assigns mongodb, unifi, marrytts and postgres to one node in one
assert.doesNotMatch(mongoRes.out, /authentication failed/i,
`mongodb delivered a credential that does not authenticate:\n${mongoRes.out}\n---runtime log---\n${(await on(`docker logs mesh-mongodb 2>&1 | tail -30`)).out}`);
assert.match(mongoRes.out, /MONGO_OK/,
`the consumer could not use its granted database as ${mongoAs}:\n${mongoRes.out}`);
`the consumer could not use its granted database as ${mongoAs}:\n${mongoRes.out}\n---containers---\n` +
`${(await on(`docker ps -a --format '{{.Names}} {{.Status}}'`)).out}\n---mongo log---\n` +
`${(await on(`docker logs mongo 2>&1 | tail -15`)).out}`);
// --- mongodb and unifi serve their tools over their scoped accounts -------------------------------
let served = "";