ADRs 0091 and 0092; issues 026 and 070 resolved; designs 18 and 24 amended
This commit is contained in:
@@ -7,6 +7,7 @@ code:
|
||||
- mesh-catalog modules/builder
|
||||
updated: 2026-09-21
|
||||
decisions:
|
||||
- 02-DECISIONS/0091-a-mount-is-declared-three-ways.md
|
||||
- 02-DECISIONS/0087-a-seeded-file-is-created-once.md
|
||||
- 02-DECISIONS/0040-what-a-module-is.md
|
||||
- 02-DECISIONS/0039-what-the-sdk-holds-and-refuses.md
|
||||
@@ -182,6 +183,16 @@ disagrees with it.
|
||||
| `computed` | marks a module the controller generates rather than an author writing |
|
||||
| `build.artifacts` | what it produces |
|
||||
|
||||
**A container mounts only what the manifest declares**
|
||||
([ADR 0091](../../02-DECISIONS/0091-a-mount-is-declared-three-ways.md)). A bind mount the module
|
||||
never declared is created by the container runtime as root, so the module's owner and mode never
|
||||
reach its data and the rule that keeps data when a module goes away does not cover it. A path is
|
||||
declared in one of three ways, for the three things a path can be: the module's own (a directory
|
||||
or file resource, or where a secret, grant or contribution lands), the operator's (an `accesses`
|
||||
entry), or the machine's (a facility a declared capability grants — `container-runtime` grants its
|
||||
socket). *How it is checked:* the parser refuses an undeclared mount naming the path and the three
|
||||
remedies, and a test parses every manifest in the catalogue beside the checkout.
|
||||
|
||||
### What it builds
|
||||
|
||||
| kind | is |
|
||||
|
||||
@@ -4,6 +4,7 @@ status: implemented
|
||||
code: [mesh-catalog, mesh-controller, mesh-host]
|
||||
updated: 2026-09-21
|
||||
decisions:
|
||||
- 02-DECISIONS/0092-an-operator-delivers-a-pair-credential.md
|
||||
- 02-DECISIONS/0085-a-secret-is-a-provision.md
|
||||
- 02-DECISIONS/0031-the-control-plane-authenticates-nobody.md
|
||||
- 02-DECISIONS/0048-a-provider-creates-the-credential-the-mesh-minted.md
|
||||
@@ -45,7 +46,12 @@ whose job it is to give it one."*
|
||||
|
||||
A module that needs a secret for its own use requires a `secret` provision, exactly as it requires
|
||||
a database from the store. The vault generates the value — or takes custody of one an operator
|
||||
delivered — and the credential belongs to the consumer↔vault pair. Because it is an ordinary pair
|
||||
delivered, through `secret accept … --provider`, which seals it to both ends and records the pair
|
||||
as accepted ([ADR 0092](../../02-DECISIONS/0092-an-operator-delivers-a-pair-credential.md)) — and
|
||||
the credential belongs to the consumer↔vault pair. An accepted pair is the one exception to what
|
||||
follows: the mesh cannot make its replacement, so it is neither remade when a key changes nor
|
||||
rotated; both are refused aloud, and accepting a new value is the rotation. *How it is checked:*
|
||||
an inventory test accepts, reads back unchanged, and asserts the two refusals name the remedy. Because it is an ordinary pair
|
||||
credential, **everything already built for pair credentials applies to it unchanged**: it rotates
|
||||
with the one command that discards a credential and delivers both ends together, it is one secret
|
||||
per holder so rotating one touches nothing else, and *who holds this* is a query rather than an
|
||||
|
||||
Reference in New Issue
Block a user