ADR 0113 and to-be 27: address the review of the vault rework
Two decisions taken with the author: - Genesis delivers and the vault adopts. The vault cannot run first — it is built on the runtime base the installation makes after the store, broker and controller, and it learns its work over the bus. Genesis generates the foundation's first shared secrets, seals them to the operator key, and delivers them to the vault through the path an operator's value takes; from then on the vault holds and rotates them. This answers ADR 0085's own reason for rejecting vault-only minting, which 0113 now names instead of stepping around. - Rotation re-confirms on every pass. An applier repeats its confirmation until acknowledged, so a lost message costs one pass; an applier that stops after applying locks readers out until its supervised restart, and that window is stated and shown, not claimed away. Fixes: - Scope: a shared secret is made by the vault; a private key (node sealing keys, the operator's key, the certificate authority) is made where it is used. The inventory adds the makers the first version missed: node and builder broker passwords, and enrolment tokens. - Broker accounts are created by the broker's provisioner, not the controller, so the controller never holds their plaintext; mesh-broker delivers amqp again — one broker per mesh — and only mesh-store delivers nothing. - secret is a reserved provision: only the mesh-vault holder may provide it, and no pin routes around it. - A secret's contract says whether a recipient applies it or reads it at start; appliers are never restarted for it, init-only secrets are applied, and confirmation is to-be 13's standard. - Operator secrets are one rule everywhere: a secret requirement answered by the vault (0112 no longer says otherwise). A data provider's adapter may return fields; the data-return check names a lab consumer. - 'Holder' now means a seat's holder only; a secret has recipients.
This commit is contained in:
@@ -48,8 +48,8 @@ argued for is an entry nobody can explain.
|
||||
|---|---|---|---|
|
||||
| `mesh-controller` | mesh | — | the controller |
|
||||
| `mesh-store` | mesh | — | the foundation's store |
|
||||
| `mesh-broker` | mesh | — | the foundation's broker |
|
||||
| `mesh-vault` | mesh | `secret` | the vault |
|
||||
| `mesh-broker` | mesh | `amqp` | the broker |
|
||||
| `mesh-vault` | mesh | `secret`, reserved | the vault |
|
||||
| `the-artifact-store` | mesh | `artifact-store` | the artifact registry |
|
||||
| `the-catalogue` | mesh | — | the catalogue |
|
||||
| `npm-package-registry` | mesh | `npm-package-registry` | the forge |
|
||||
@@ -64,8 +64,8 @@ argued for is an entry nobody can explain.
|
||||
|
||||
The controller holds this set in code, and a test asserts both its size and that every entry names
|
||||
the record that made it a seat. **This table and [ADR 0110](../../02-DECISIONS/0110-a-seat-is-a-module-assignment-from-a-closed-set.md)
|
||||
govern, and code that disagrees is what is wrong.** The implementation in progress predates two
|
||||
things here: the `mesh-vault` seat, and the rule that `mesh-store` and `mesh-broker` deliver
|
||||
govern, and code that disagrees is what is wrong.** The implementation in progress predates three
|
||||
things here: the `mesh-vault` seat and its reservation, and the rule that `mesh-store` delivers
|
||||
nothing. It is brought to this table before it merges.
|
||||
|
||||
## A seat that delivers a provision
|
||||
@@ -73,11 +73,18 @@ nothing. It is brought to this table before it merges.
|
||||
A seat that delivers a provision may only be held by a module that provides it, at the seat's scope.
|
||||
A mesh seat delivers a mesh-scoped provision.
|
||||
|
||||
**A seat delivers a provision only where the mesh has one answer for everyone.** The artifact store,
|
||||
the npm registry, git and the vault are each one per mesh by decision. The store and the broker are
|
||||
**A seat delivers a provision only where the mesh has one answer for everyone.** The broker, the
|
||||
artifact store, the npm registry, git and the vault are each one per mesh by decision. The store is
|
||||
not: nodes run their own stores and a consumer uses the one on its machine
|
||||
([23 — Choosing a provider](23-choosing-a-provider.md)). So their seats guard that the foundation's
|
||||
own server is singular, and route nobody.
|
||||
([23 — Choosing a provider](23-choosing-a-provider.md)), and the foundation's store is the controller's
|
||||
own memory, provider to nobody. So `mesh-store` guards that the foundation's store is singular, and
|
||||
routes nobody.
|
||||
|
||||
**The vault's provision is reserved.** Only the holder of `mesh-vault` may provide `secret` at all: a
|
||||
module providing it without the seat is refused, and a pin cannot choose another provider, because
|
||||
there is none. A second provider of secrets would be a second place secrets live, which is what the
|
||||
vault being one per mesh exists to prevent. Every other delivered provision may have second
|
||||
providers, which a pin can choose.
|
||||
|
||||
**Its holder answers for that provision.** A requirement for it resolves, in order, to:
|
||||
|
||||
|
||||
Reference in New Issue
Block a user