User Tools

Site Tools


zededa:sharing-persist-volume-by-two-apps

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
zededa:sharing-persist-volume-by-two-apps [2026/07/24 15:16] – mczededa:sharing-persist-volume-by-two-apps [2026/07/24 15:26] (current) – mc
Line 159: Line 159:
   * **Build container images with ''--provenance=false --sbom=false''** — clean hygiene (avoids "unknown/unknown" attestation manifests in the index). Not strictly required for ZEDEDA to accept the image, but good practice.   * **Build container images with ''--provenance=false --sbom=false''** — clean hygiene (avoids "unknown/unknown" attestation manifests in the index). Not strictly required for ZEDEDA to accept the image, but good practice.
   * **9P mount tag is ''share_dir''** (a literal in EVE ''hypervisor/kvm.go''), and it's triggered by the drive's **CONTAINER format**, not by ''mountpath''.   * **9P mount tag is ''share_dir''** (a literal in EVE ''hypervisor/kvm.go''), and it's triggered by the drive's **CONTAINER format**, not by ''mountpath''.
 +
 +===== Updating the config (runbook) =====
 +
 +Push a new config version **without** redeploying the image, app, VMs, or volumes —
 +you only recreate the patch envelope. The writer auto-fetches it on its next poll and
 +drops a new versioned file into ''/data''.
 +
 +<code bash>
 +# 1. Edit the config artifact
 +$EDITOR Demo-Hummingbird/c-init/patch-config.json
 +
 +# 2. Bump the version on the envelope in 6-Instances-Deploy-hum.tf
 +#    user_defined_version = "2.0"  ->  "3.0"
 +
 +# 3. Recreate the envelope + its binding (in-place update is rejected -> -replace)
 +terraform apply \
 +  -replace='zedcloud_patch_envelope.tf_demo_config_pe' \
 +  -replace='zedcloud_patch_reference_update.tf_demo_config_pe_bind'
 +
 +# 4. Wait ~30-60s (controller -> device propagation + the writer's poll interval)
 +
 +# 5. Verify (on the writer container or any reader VM)
 +cat /data/config.latest.json      # new content
 +cat /data/config.history          # <ts>  <sha> per version
 +#    writer log line: [pcw] new config.json (v=3.0) -> /data/config-<ts>.json (sha=...)
 +</code>
 +
 +  * **''-replace'' both resources:** an in-place artifact update returns HTTP 400; and the envelope's ID changes on recreate, so the ''patch_reference_update'' binding must be recreated to re-point at it.
 +  * **Bumping ''user_defined_version''** is recommended (labels the version, shows in the metadata ''Version'' field and the writer log) but not strictly required — the writer detects change by content SHA.
 +  * **You do NOT touch** the container image, the writer app, the VMs, or the volumes. That is the whole point of the patch-envelope design: config changes with nothing redeployed.
 +
 +==== First-time deploy (for reference) ====
 +
 +<code bash>
 +# build + push the writer image (clean manifest — no attestation entries)
 +docker buildx build --platform linux/amd64,linux/arm64 --provenance=false --sbom=false \
 +  -t zedmanny/patch-config-writer:1.2.0 --push .
 +
 +# bring everything up
 +terraform apply
 +
 +# if the image was already created and you changed its tag, the image is immutable AND
 +# held by the app -> recreate the whole chain in one apply:
 +terraform apply \
 +  -replace='zedcloud_application_instance.tf_patch_config_writer_1' \
 +  -replace='zedcloud_application.tf_patch_config_writer_app' \
 +  -replace='zedcloud_image.demo_patch_config_writer'
 +</code>
  
 ===== Sources ===== ===== Sources =====
zededa/sharing-persist-volume-by-two-apps.1784906185.txt.gz · Last modified: by mc