ADRs 0091 and 0092; issues 026 and 070 resolved; designs 18 and 24 amended

This commit is contained in:
2026-09-21 17:50:41 +02:00
parent ffb7fa52ec
commit 16442ecd23
9 changed files with 183 additions and 8 deletions
@@ -1,9 +1,9 @@
---
status: open
status: resolved
opened: 2026-09-20
located-in: [mesh-controller]
fixed-by:
amended-design:
located-in: [mesh-controller internal/inventory (secret), mesh-controller cmd/mesh-controller (secret accept)]
fixed-by: ADR 0092; mesh-controller feat/multiple-fixes (secret accept --provider; origin on the pair; remake and rotate refused)
amended-design: 03-DESIGN/01-to-be/24-the-secrets-vault.md
---
# An operator cannot deliver a pair credential, so the vault's third species has no entry
@@ -0,0 +1,13 @@
# Diagnosis — 2026-09-21
1. The three open questions, answered. It is `secret accept` growing a provider end, not a new
verb: the verb already means a value a person supplied, sealed on the way in. An accepted pair
refuses `rotate` — the mesh cannot make the replacement — and accepting a new value is the
rotation. The origin becomes a fact of every pair credential, `made` or `accepted`, so the
vault's ledger can say which a person supplied.
2. One consequence the report did not name: a pair credential is remade whenever either end's
sealing key changes, and an accepted one cannot be — the mesh does not hold the value. The
read is refused aloud with the remedy rather than quietly replaced by a minted one.
**Located in:** the controller's pair-credential store and the `secret accept` command. Decided
in [ADR 0092](../../02-DECISIONS/0092-an-operator-delivers-a-pair-credential.md).