Beds for the seed file and the foundation's filter; beds deliver secrets as files; a bundle-raised bed derives the anchor's filter #40
@@ -220,14 +220,13 @@ test("the mesh assigns mongodb, unifi, marrytts and postgres to one node in one
|
|||||||
{ id: "mesh-state", type: "directory", path: "/var/lib/mesh/mongodb", mode: "0700" },
|
{ id: "mesh-state", type: "directory", path: "/var/lib/mesh/mongodb", mode: "0700" },
|
||||||
{ id: "state", type: "directory", path: "/var/lib/mongodb", mode: "0700" },
|
{ id: "state", type: "directory", path: "/var/lib/mongodb", mode: "0700" },
|
||||||
{ id: "grants", type: "directory", path: "/var/lib/mongodb/grants", mode: "0700" },
|
{ id: "grants", type: "directory", path: "/var/lib/mongodb/grants", mode: "0700" },
|
||||||
{ id: "root-env", type: "file", path: "/var/lib/mongodb/root.env", mode: "0600", content: "MONGO_INITDB_ROOT_PASSWORD=${secret:root}\n" },
|
|
||||||
{ id: "data", type: "directory", path: "/services/mongodb/db-data", mode: "0700" },
|
{ id: "data", type: "directory", path: "/services/mongodb/db-data", mode: "0700" },
|
||||||
{ id: "net", type: "network", name: "mongodb" },
|
{ id: "net", type: "network", name: "mongodb" },
|
||||||
{
|
{
|
||||||
id: "server", type: "container", name: "mongo", image: pinned("mongo"), network: "mongodb",
|
id: "server", type: "container", name: "mongo", image: pinned("mongo"), network: "mongodb",
|
||||||
env: { MONGO_INITDB_ROOT_USERNAME: "root" },
|
// The root password reaches mongo as a file (novox/hq ADR 0086), the shape the catalogue's manifest has.
|
||||||
"env-file": ["/var/lib/mongodb/root.env"],
|
env: { MONGO_INITDB_ROOT_USERNAME: "root", MONGO_INITDB_ROOT_PASSWORD_FILE: "/run/secrets/root" },
|
||||||
volumes: ["/services/mongodb/db-data:/data/db"],
|
volumes: ["/services/mongodb/db-data:/data/db", "/var/lib/mongodb/root.secret:/run/secrets/root:ro"],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
id: "runtime", type: "container", name: "mesh-mongodb", image: pinned("mesh-runtime-mongodb"),
|
id: "runtime", type: "container", name: "mesh-mongodb", image: pinned("mesh-runtime-mongodb"),
|
||||||
|
|||||||
@@ -229,14 +229,16 @@ test("the mesh assigns postgres, redis, minio and plex to one node in one push,
|
|||||||
{ id: "mesh-state", type: "directory", path: "/var/lib/mesh/minio", mode: "0700" },
|
{ id: "mesh-state", type: "directory", path: "/var/lib/mesh/minio", mode: "0700" },
|
||||||
{ id: "state", type: "directory", path: "/var/lib/minio", mode: "0700" },
|
{ id: "state", type: "directory", path: "/var/lib/minio", mode: "0700" },
|
||||||
{ id: "grants", type: "directory", path: "/var/lib/minio/grants", mode: "0700" },
|
{ id: "grants", type: "directory", path: "/var/lib/minio/grants", mode: "0700" },
|
||||||
{ id: "root-env", type: "file", path: "/var/lib/minio/root.env", mode: "0600", content: "MINIO_ROOT_USER=meshroot\nMINIO_ROOT_PASSWORD=${secret:root}\n" },
|
// The root password reaches minio as a file (novox/hq ADR 0086), the shape the catalogue's manifest has.
|
||||||
|
{ id: "root-env", type: "file", path: "/var/lib/minio/root.env", mode: "0600", content: "MINIO_ROOT_USER=meshroot\n" },
|
||||||
{ id: "data", type: "directory", path: "/services/minio/data/data1-1", mode: "0700" },
|
{ id: "data", type: "directory", path: "/services/minio/data/data1-1", mode: "0700" },
|
||||||
{ id: "net", type: "network", name: "minio" },
|
{ id: "net", type: "network", name: "minio" },
|
||||||
{
|
{
|
||||||
id: "server", type: "container", name: "minio", image: pinned("minio/minio"), network: "minio",
|
id: "server", type: "container", name: "minio", image: pinned("minio/minio"), network: "minio",
|
||||||
args: ["server", "/data", "--console-address", ":9001"],
|
args: ["server", "/data", "--console-address", ":9001"],
|
||||||
"env-file": ["/var/lib/minio/root.env"],
|
"env-file": ["/var/lib/minio/root.env"],
|
||||||
volumes: ["/services/minio/data/data1-1:/data"],
|
env: { MINIO_ROOT_PASSWORD_FILE: "/run/secrets/root" },
|
||||||
|
volumes: ["/services/minio/data/data1-1:/data", "/var/lib/minio/root.secret:/run/secrets/root:ro"],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
id: "runtime", type: "container", name: "mesh-minio", image: pinned("mesh-runtime-minio"),
|
id: "runtime", type: "container", name: "mesh-minio", image: pinned("mesh-runtime-minio"),
|
||||||
|
|||||||
@@ -249,10 +249,12 @@ test("usage events are upserted into model-usage's store — latest-per-key, bot
|
|||||||
resources: [
|
resources: [
|
||||||
{ id: "mesh-state", type: "directory", path: "/var/lib/mesh/model-usage", mode: "0700" },
|
{ id: "mesh-state", type: "directory", path: "/var/lib/mesh/model-usage", mode: "0700" },
|
||||||
{ id: "state", type: "directory", path: "/var/lib/model-usage", mode: "0700" },
|
{ id: "state", type: "directory", path: "/var/lib/model-usage", mode: "0700" },
|
||||||
|
// The connection string carries the password, so it reaches the runtime as a file the mesh
|
||||||
|
// templates (novox/hq ADR 0086), the shape the catalogue's manifest has.
|
||||||
{
|
{
|
||||||
id: "db-env", type: "file", path: "/var/lib/model-usage/db.env", mode: "0600",
|
id: "database-url", type: "file", path: "/var/lib/model-usage/database.url", mode: "0600",
|
||||||
content:
|
content:
|
||||||
"DATABASE_URL=postgresql://${bound:postgres-database:as}:${secret:postgres-database}@" +
|
"postgresql://${bound:postgres-database:as}:${secret:postgres-database}@" +
|
||||||
"${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\n",
|
"${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\n",
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
@@ -261,9 +263,9 @@ test("usage events are upserted into model-usage's store — latest-per-key, bot
|
|||||||
volumes: [
|
volumes: [
|
||||||
"/var/lib/mesh/model-usage/broker:/run/secrets/broker:ro",
|
"/var/lib/mesh/model-usage/broker:/run/secrets/broker:ro",
|
||||||
"/var/lib/model-usage:/run/state",
|
"/var/lib/model-usage:/run/state",
|
||||||
|
"/var/lib/model-usage/database.url:/run/secrets/database-url:ro",
|
||||||
],
|
],
|
||||||
env: { MESH_BROKER_FILE: "/run/secrets/broker" },
|
env: { MESH_BROKER_FILE: "/run/secrets/broker", DATABASE_URL_FILE: "/run/secrets/database-url" },
|
||||||
"env-file": ["/var/lib/model-usage/db.env"],
|
|
||||||
},
|
},
|
||||||
],
|
],
|
||||||
});
|
});
|
||||||
|
|||||||
Reference in New Issue
Block a user