The apps bed's mongodb names its secrets' owner, as the catalogue's does, and says what the server said when the consumer cannot reach it
This commit is contained in:
@@ -215,6 +215,8 @@ test("the mesh assigns mongodb, unifi, marrytts and postgres to one node in one
|
|||||||
receives: { "mongodb-database": "/var/lib/mongodb/grants/mesh.json" },
|
receives: { "mongodb-database": "/var/lib/mongodb/grants/mesh.json" },
|
||||||
grants: { "mongodb-database": "/var/lib/mongodb/grants" },
|
grants: { "mongodb-database": "/var/lib/mongodb/grants" },
|
||||||
"own-secrets": { root: "/var/lib/mongodb/root.secret", broker: "/var/lib/mesh/mongodb/broker" },
|
"own-secrets": { root: "/var/lib/mongodb/root.secret", broker: "/var/lib/mesh/mongodb/broker" },
|
||||||
|
// The image drops to its own user before it reads the password file (ADR 0086; as the catalogue's).
|
||||||
|
"secrets-owner": "999:999",
|
||||||
resources: [
|
resources: [
|
||||||
{ id: "mesh-state", type: "directory", path: "/var/lib/mesh/mongodb", mode: "0700" },
|
{ id: "mesh-state", type: "directory", path: "/var/lib/mesh/mongodb", mode: "0700" },
|
||||||
{ id: "state", type: "directory", path: "/var/lib/mongodb", mode: "0700" },
|
{ id: "state", type: "directory", path: "/var/lib/mongodb", mode: "0700" },
|
||||||
@@ -413,7 +415,9 @@ test("the mesh assigns mongodb, unifi, marrytts and postgres to one node in one
|
|||||||
assert.doesNotMatch(mongoRes.out, /authentication failed/i,
|
assert.doesNotMatch(mongoRes.out, /authentication failed/i,
|
||||||
`mongodb delivered a credential that does not authenticate:\n${mongoRes.out}\n---runtime log---\n${(await on(`docker logs mesh-mongodb 2>&1 | tail -30`)).out}`);
|
`mongodb delivered a credential that does not authenticate:\n${mongoRes.out}\n---runtime log---\n${(await on(`docker logs mesh-mongodb 2>&1 | tail -30`)).out}`);
|
||||||
assert.match(mongoRes.out, /MONGO_OK/,
|
assert.match(mongoRes.out, /MONGO_OK/,
|
||||||
`the consumer could not use its granted database as ${mongoAs}:\n${mongoRes.out}`);
|
`the consumer could not use its granted database as ${mongoAs}:\n${mongoRes.out}\n---containers---\n` +
|
||||||
|
`${(await on(`docker ps -a --format '{{.Names}} {{.Status}}'`)).out}\n---mongo log---\n` +
|
||||||
|
`${(await on(`docker logs mongo 2>&1 | tail -15`)).out}`);
|
||||||
|
|
||||||
// --- mongodb and unifi serve their tools over their scoped accounts -------------------------------
|
// --- mongodb and unifi serve their tools over their scoped accounts -------------------------------
|
||||||
let served = "";
|
let served = "";
|
||||||
|
|||||||
Reference in New Issue
Block a user