fix(S2-a): mount broker auth files outside source tree

This commit is contained in:
Brent Perteet
2026-08-20 15:53:20 -05:00
parent 8aea87c3cd
commit e552ae4e5c
3 changed files with 12 additions and 9 deletions

View File

@@ -28,7 +28,9 @@ and are excluded from Git.
The live password database is likewise outside Git at The live password database is likewise outside Git at
`/home/ubuntu/.config/ul-platform/mosquitto.passwd`, bind-mounted read-only as `/home/ubuntu/.config/ul-platform/mosquitto.passwd`, bind-mounted read-only as
`/mosquitto/secrets/passwd`. Provisioning updates that host file and restarts Mosquitto; the `/run/secrets/mosquitto_passwd`. The deployed ACL is copied to
`/home/ubuntu/.config/ul-platform/mosquitto.acl` and bind-mounted beside it. Both files are owned
by broker uid/gid 1883 with mode 0600. Provisioning updates the host password file and restarts Mosquitto; the
tracked `mosquitto/config/passwd` is only a legacy/bootstrap sample and must not receive new tracked `mosquitto/config/passwd` is only a legacy/bootstrap sample and must not receive new
organization credentials. organization credentials.

View File

@@ -16,7 +16,8 @@ services:
- "127.0.0.1:9001:9001" - "127.0.0.1:9001:9001"
volumes: volumes:
- ./mosquitto:/mosquitto - ./mosquitto:/mosquitto
- /home/ubuntu/.config/ul-platform/mosquitto.passwd:/mosquitto/secrets/passwd:ro - /home/ubuntu/.config/ul-platform/mosquitto.passwd:/run/secrets/mosquitto_passwd:ro
- /home/ubuntu/.config/ul-platform/mosquitto.acl:/run/secrets/mosquitto_acl:ro
backend: backend:
build: build:

View File

@@ -2,16 +2,16 @@ per_listener_settings true
# Plain MQTT — internal services and clients authenticate with username/password on port 1883 # Plain MQTT — internal services and clients authenticate with username/password on port 1883
listener 1883 0.0.0.0 listener 1883 0.0.0.0
password_file /mosquitto/secrets/passwd password_file /run/secrets/mosquitto_passwd
acl_file /mosquitto/config/devices.acl acl_file /run/secrets/mosquitto_acl
allow_anonymous false allow_anonymous false
# Authenticated MQTT over WebSocket for app clients. Docker binds this listener only to # Authenticated MQTT over WebSocket for app clients. Docker binds this listener only to
# host loopback; nginx supplies the public WSS/TLS endpoint at /mqtt on port 443. # host loopback; nginx supplies the public WSS/TLS endpoint at /mqtt on port 443.
listener 9001 0.0.0.0 listener 9001 0.0.0.0
protocol websockets protocol websockets
password_file /mosquitto/secrets/passwd password_file /run/secrets/mosquitto_passwd
acl_file /mosquitto/config/devices.acl acl_file /run/secrets/mosquitto_acl
allow_anonymous false allow_anonymous false
# TLS MQTT — devices authenticate with client certificates (port 8883) # TLS MQTT — devices authenticate with client certificates (port 8883)
@@ -27,7 +27,7 @@ keyfile /mosquitto/certs/public-privkey.pem
require_certificate true require_certificate true
use_identity_as_username true use_identity_as_username true
allow_anonymous false allow_anonymous false
acl_file /mosquitto/config/devices.acl acl_file /run/secrets/mosquitto_acl
# TLS MQTT — app/admin username+password access (port 8884). App usernames are orgIds; # TLS MQTT — app/admin username+password access (port 8884). App usernames are orgIds;
# devices.acl confines them to ul/{orgId}/app/... . No anonymous listener is exposed. # devices.acl confines them to ul/{orgId}/app/... . No anonymous listener is exposed.
@@ -35,6 +35,6 @@ listener 8884 0.0.0.0
certfile /mosquitto/certs/public-fullchain.pem certfile /mosquitto/certs/public-fullchain.pem
keyfile /mosquitto/certs/public-privkey.pem keyfile /mosquitto/certs/public-privkey.pem
require_certificate false require_certificate false
password_file /mosquitto/secrets/passwd password_file /run/secrets/mosquitto_passwd
allow_anonymous false allow_anonymous false
acl_file /mosquitto/config/devices.acl acl_file /run/secrets/mosquitto_acl