Designs 07 and 21 and issue 071: genesis now makes the root secrets

The installer half of the amended ADR 0085 is built and proven by the
genesis bed's root-secrets step; the foundation design closes its open item
and the installation design says what the installer does and what it still
cannot check.
This commit is contained in:
2026-09-21 00:50:56 +02:00
parent 8607d21110
commit 1bce3f33a8
3 changed files with 25 additions and 16 deletions
@@ -1,8 +1,8 @@
---
status: located
status: resolved
opened: 2026-09-20
located-in: [mesh-host internal/bootstrap, mesh-host examples/foundation-first-node.lock]
fixed-by:
fixed-by: mesh-host feat/secrets-vault (ee0c8b8, genesis root credentials + operator key + vault); mesh-controller feat/secrets-vault (e140ed5, 565f144); mesh-catalog feat/secrets-vault; proven by the one-node genesis bed step V5
amended-design: 03-DESIGN/01-to-be/24-the-secrets-vault.md
---
@@ -35,5 +35,7 @@ rests on are not random, and there is no operator key at genesis for anything to
[24](../../03-DESIGN/01-to-be/24-the-secrets-vault.md): genesis makes the operator key first,
mints real credentials for the store and broker before the bundle raises them (or changes them
on the running servers before handing over), accepts those, and installs `mesh-vault` so the
operator-sealed export exists from the first push. The controller's half — the key, the second
seal, export and recovery — is built; the installer's half is not.
operator-sealed export exists from the first push. Built on `feat/secrets-vault` across mesh-host, mesh-controller and mesh-catalog, and proven by
the one-node genesis bed: the template's password is refused by the store, the export and the
vault's copy hold no plaintext, and the superuser recovered off the mesh with the operator key
opens the store.