The three beds' inline postgres reads its superuser from a file, as the catalogue's does
This commit is contained in:
@@ -168,14 +168,13 @@ test("the mesh assigns mongodb, unifi, marrytts and postgres to one node in one
|
|||||||
{ id: "mesh-state", type: "directory", path: "/var/lib/mesh/postgres", mode: "0700" },
|
{ id: "mesh-state", type: "directory", path: "/var/lib/mesh/postgres", mode: "0700" },
|
||||||
{ id: "state", type: "directory", path: "/var/lib/postgres", mode: "0700" },
|
{ id: "state", type: "directory", path: "/var/lib/postgres", mode: "0700" },
|
||||||
{ id: "grants", type: "directory", path: "/var/lib/postgres/grants", mode: "0700" },
|
{ id: "grants", type: "directory", path: "/var/lib/postgres/grants", mode: "0700" },
|
||||||
{ id: "superuser-env", type: "file", path: "/var/lib/postgres/superuser.env", mode: "0600", content: "POSTGRES_PASSWORD=${secret:superuser}\n" },
|
|
||||||
{ id: "data", type: "directory", path: "/services/postgres/db-data", mode: "0700" },
|
{ id: "data", type: "directory", path: "/services/postgres/db-data", mode: "0700" },
|
||||||
{ id: "net", type: "network", name: "postgres" },
|
{ id: "net", type: "network", name: "postgres" },
|
||||||
{
|
{
|
||||||
id: "server", type: "container", name: "postgres", image: pinned("postgres"), network: "postgres",
|
id: "server", type: "container", name: "postgres", image: pinned("postgres"), network: "postgres",
|
||||||
env: { POSTGRES_USER: "postgres", POSTGRES_DB: "postgres" },
|
// The superuser reaches postgres as a file (novox/hq ADR 0086), the shape the catalogue's manifest has.
|
||||||
"env-file": ["/var/lib/postgres/superuser.env"],
|
env: { POSTGRES_USER: "postgres", POSTGRES_DB: "postgres", POSTGRES_PASSWORD_FILE: "/run/secrets/superuser" },
|
||||||
volumes: ["/services/postgres/db-data:/var/lib/postgresql/data"],
|
volumes: ["/services/postgres/db-data:/var/lib/postgresql/data", "/var/lib/postgres/superuser.secret:/run/secrets/superuser:ro"],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
id: "runtime", type: "container", name: "mesh-postgres", image: pinned("mesh-runtime-postgres"),
|
id: "runtime", type: "container", name: "mesh-postgres", image: pinned("mesh-runtime-postgres"),
|
||||||
|
|||||||
@@ -178,14 +178,13 @@ test("the mesh assigns postgres, redis, minio and plex to one node in one push,
|
|||||||
{ id: "mesh-state", type: "directory", path: "/var/lib/mesh/postgres", mode: "0700" },
|
{ id: "mesh-state", type: "directory", path: "/var/lib/mesh/postgres", mode: "0700" },
|
||||||
{ id: "state", type: "directory", path: "/var/lib/postgres", mode: "0700" },
|
{ id: "state", type: "directory", path: "/var/lib/postgres", mode: "0700" },
|
||||||
{ id: "grants", type: "directory", path: "/var/lib/postgres/grants", mode: "0700" },
|
{ id: "grants", type: "directory", path: "/var/lib/postgres/grants", mode: "0700" },
|
||||||
{ id: "superuser-env", type: "file", path: "/var/lib/postgres/superuser.env", mode: "0600", content: "POSTGRES_PASSWORD=${secret:superuser}\n" },
|
|
||||||
{ id: "data", type: "directory", path: "/services/postgres/db-data", mode: "0700" },
|
{ id: "data", type: "directory", path: "/services/postgres/db-data", mode: "0700" },
|
||||||
{ id: "net", type: "network", name: "postgres" },
|
{ id: "net", type: "network", name: "postgres" },
|
||||||
{
|
{
|
||||||
id: "server", type: "container", name: "postgres", image: pinned("postgres"), network: "postgres",
|
id: "server", type: "container", name: "postgres", image: pinned("postgres"), network: "postgres",
|
||||||
env: { POSTGRES_USER: "postgres", POSTGRES_DB: "postgres" },
|
// The superuser reaches postgres as a file (novox/hq ADR 0086), the shape the catalogue's manifest has.
|
||||||
"env-file": ["/var/lib/postgres/superuser.env"],
|
env: { POSTGRES_USER: "postgres", POSTGRES_DB: "postgres", POSTGRES_PASSWORD_FILE: "/run/secrets/superuser" },
|
||||||
volumes: ["/services/postgres/db-data:/var/lib/postgresql/data"],
|
volumes: ["/services/postgres/db-data:/var/lib/postgresql/data", "/var/lib/postgres/superuser.secret:/run/secrets/superuser:ro"],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
id: "runtime", type: "container", name: "mesh-postgres", image: pinned("mesh-runtime-postgres"),
|
id: "runtime", type: "container", name: "mesh-postgres", image: pinned("mesh-runtime-postgres"),
|
||||||
|
|||||||
@@ -202,15 +202,14 @@ test("usage events are upserted into model-usage's store — latest-per-key, bot
|
|||||||
{ id: "mesh-state", type: "directory", path: "/var/lib/mesh/postgres", mode: "0700" },
|
{ id: "mesh-state", type: "directory", path: "/var/lib/mesh/postgres", mode: "0700" },
|
||||||
{ id: "state", type: "directory", path: "/var/lib/postgres", mode: "0700" },
|
{ id: "state", type: "directory", path: "/var/lib/postgres", mode: "0700" },
|
||||||
{ id: "grants", type: "directory", path: "/var/lib/postgres/grants", mode: "0700" },
|
{ id: "grants", type: "directory", path: "/var/lib/postgres/grants", mode: "0700" },
|
||||||
{ id: "superuser-env", type: "file", path: "/var/lib/postgres/superuser.env", mode: "0600", content: "POSTGRES_PASSWORD=${secret:superuser}\n" },
|
|
||||||
{ id: "data", type: "directory", path: "/services/postgres/db-data", mode: "0700" },
|
{ id: "data", type: "directory", path: "/services/postgres/db-data", mode: "0700" },
|
||||||
{ id: "net", type: "network", name: "postgres" },
|
{ id: "net", type: "network", name: "postgres" },
|
||||||
{
|
{
|
||||||
id: "server", type: "container", name: "postgres", image: pinned("postgres"), network: "postgres",
|
id: "server", type: "container", name: "postgres", image: pinned("postgres"), network: "postgres",
|
||||||
env: { POSTGRES_USER: "postgres", POSTGRES_DB: "postgres" },
|
// The superuser reaches postgres as a file (novox/hq ADR 0086), the shape the catalogue's manifest has.
|
||||||
"env-file": ["/var/lib/postgres/superuser.env"],
|
env: { POSTGRES_USER: "postgres", POSTGRES_DB: "postgres", POSTGRES_PASSWORD_FILE: "/run/secrets/superuser" },
|
||||||
ports: ["5432"],
|
ports: ["5432"],
|
||||||
volumes: ["/services/postgres/db-data:/var/lib/postgresql/data"],
|
volumes: ["/services/postgres/db-data:/var/lib/postgresql/data", "/var/lib/postgres/superuser.secret:/run/secrets/superuser:ro"],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
id: "runtime", type: "container", name: "mesh-postgres", image: pinned("mesh-runtime-postgres"),
|
id: "runtime", type: "container", name: "mesh-postgres", image: pinned("mesh-runtime-postgres"),
|
||||||
|
|||||||
Reference in New Issue
Block a user