From b7316d40fe392806fcd56ccb25096a2821d5fc3b Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 21 Sep 2026 12:55:35 +0200 Subject: [PATCH] The three beds' inline postgres reads its superuser from a file, as the catalogue's does --- test/integration/assigned-catalogue-apps.test.ts | 7 +++---- test/integration/assigned-catalogue-small.test.ts | 7 +++---- test/integration/assigned-model-usage.test.ts | 7 +++---- 3 files changed, 9 insertions(+), 12 deletions(-) diff --git a/test/integration/assigned-catalogue-apps.test.ts b/test/integration/assigned-catalogue-apps.test.ts index fd62e0e..8391c5e 100644 --- a/test/integration/assigned-catalogue-apps.test.ts +++ b/test/integration/assigned-catalogue-apps.test.ts @@ -168,14 +168,13 @@ test("the mesh assigns mongodb, unifi, marrytts and postgres to one node in one { id: "mesh-state", type: "directory", path: "/var/lib/mesh/postgres", mode: "0700" }, { id: "state", type: "directory", path: "/var/lib/postgres", mode: "0700" }, { id: "grants", type: "directory", path: "/var/lib/postgres/grants", mode: "0700" }, - { id: "superuser-env", type: "file", path: "/var/lib/postgres/superuser.env", mode: "0600", content: "POSTGRES_PASSWORD=${secret:superuser}\n" }, { id: "data", type: "directory", path: "/services/postgres/db-data", mode: "0700" }, { id: "net", type: "network", name: "postgres" }, { id: "server", type: "container", name: "postgres", image: pinned("postgres"), network: "postgres", - env: { POSTGRES_USER: "postgres", POSTGRES_DB: "postgres" }, - "env-file": ["/var/lib/postgres/superuser.env"], - volumes: ["/services/postgres/db-data:/var/lib/postgresql/data"], + // The superuser reaches postgres as a file (novox/hq ADR 0086), the shape the catalogue's manifest has. + env: { POSTGRES_USER: "postgres", POSTGRES_DB: "postgres", POSTGRES_PASSWORD_FILE: "/run/secrets/superuser" }, + volumes: ["/services/postgres/db-data:/var/lib/postgresql/data", "/var/lib/postgres/superuser.secret:/run/secrets/superuser:ro"], }, { id: "runtime", type: "container", name: "mesh-postgres", image: pinned("mesh-runtime-postgres"), diff --git a/test/integration/assigned-catalogue-small.test.ts b/test/integration/assigned-catalogue-small.test.ts index a977a75..c99e3cd 100644 --- a/test/integration/assigned-catalogue-small.test.ts +++ b/test/integration/assigned-catalogue-small.test.ts @@ -178,14 +178,13 @@ test("the mesh assigns postgres, redis, minio and plex to one node in one push, { id: "mesh-state", type: "directory", path: "/var/lib/mesh/postgres", mode: "0700" }, { id: "state", type: "directory", path: "/var/lib/postgres", mode: "0700" }, { id: "grants", type: "directory", path: "/var/lib/postgres/grants", mode: "0700" }, - { id: "superuser-env", type: "file", path: "/var/lib/postgres/superuser.env", mode: "0600", content: "POSTGRES_PASSWORD=${secret:superuser}\n" }, { id: "data", type: "directory", path: "/services/postgres/db-data", mode: "0700" }, { id: "net", type: "network", name: "postgres" }, { id: "server", type: "container", name: "postgres", image: pinned("postgres"), network: "postgres", - env: { POSTGRES_USER: "postgres", POSTGRES_DB: "postgres" }, - "env-file": ["/var/lib/postgres/superuser.env"], - volumes: ["/services/postgres/db-data:/var/lib/postgresql/data"], + // The superuser reaches postgres as a file (novox/hq ADR 0086), the shape the catalogue's manifest has. + env: { POSTGRES_USER: "postgres", POSTGRES_DB: "postgres", POSTGRES_PASSWORD_FILE: "/run/secrets/superuser" }, + volumes: ["/services/postgres/db-data:/var/lib/postgresql/data", "/var/lib/postgres/superuser.secret:/run/secrets/superuser:ro"], }, { id: "runtime", type: "container", name: "mesh-postgres", image: pinned("mesh-runtime-postgres"), diff --git a/test/integration/assigned-model-usage.test.ts b/test/integration/assigned-model-usage.test.ts index 9928511..f3c8c47 100644 --- a/test/integration/assigned-model-usage.test.ts +++ b/test/integration/assigned-model-usage.test.ts @@ -202,15 +202,14 @@ test("usage events are upserted into model-usage's store — latest-per-key, bot { id: "mesh-state", type: "directory", path: "/var/lib/mesh/postgres", mode: "0700" }, { id: "state", type: "directory", path: "/var/lib/postgres", mode: "0700" }, { id: "grants", type: "directory", path: "/var/lib/postgres/grants", mode: "0700" }, - { id: "superuser-env", type: "file", path: "/var/lib/postgres/superuser.env", mode: "0600", content: "POSTGRES_PASSWORD=${secret:superuser}\n" }, { id: "data", type: "directory", path: "/services/postgres/db-data", mode: "0700" }, { id: "net", type: "network", name: "postgres" }, { id: "server", type: "container", name: "postgres", image: pinned("postgres"), network: "postgres", - env: { POSTGRES_USER: "postgres", POSTGRES_DB: "postgres" }, - "env-file": ["/var/lib/postgres/superuser.env"], + // The superuser reaches postgres as a file (novox/hq ADR 0086), the shape the catalogue's manifest has. + env: { POSTGRES_USER: "postgres", POSTGRES_DB: "postgres", POSTGRES_PASSWORD_FILE: "/run/secrets/superuser" }, ports: ["5432"], - volumes: ["/services/postgres/db-data:/var/lib/postgresql/data"], + volumes: ["/services/postgres/db-data:/var/lib/postgresql/data", "/var/lib/postgres/superuser.secret:/run/secrets/superuser:ro"], }, { id: "runtime", type: "container", name: "mesh-postgres", image: pinned("mesh-runtime-postgres"),