ADR 0098: a fact a provider makes at first start is fetched from it; issue 076 resolved; design 08 amended; 074 down to one bed

This commit is contained in:
2026-09-21 22:27:32 +02:00
parent bc373797c7
commit 252c6042e8
6 changed files with 88 additions and 5 deletions
+11 -1
View File
@@ -7,8 +7,9 @@ code:
- mesh-controller internal/identity/authority.go
- mesh-host internal/identity/serving.go
- mesh-host internal/apply (the service that reflects a rule set)
updated: 2026-09-09
updated: 2026-09-21
decisions:
- 02-DECISIONS/0098-a-fact-a-provider-makes-at-first-start-is-fetched-from-it.md
- 02-DECISIONS/0005-the-node-host.md
- 02-DECISIONS/0004-a-node-and-how-it-joins.md
- 02-DECISIONS/0007-connectivity.md
@@ -557,6 +558,15 @@ fingerprint in its token ([ADR 0004](../../02-DECISIONS/0004-a-node-and-how-it-j
so nothing needs the CA before membership. It certifies internal names afterwards, and that is
all it does.
**The internal authority makes its own root at first start, and a consumer fetches it**
([ADR 0098](../../02-DECISIONS/0098-a-fact-a-provider-makes-at-first-start-is-fetched-from-it.md)).
The mesh mints the authority's password and nothing else of its: a root certificate and its key
are things only the authority can make, and a served fact written in a manifest cannot carry what
does not exist until the authority has run. So the authority serves its root at a path beside its
ACME directory, and the proxy that requires it fetches that root over the mesh network in a
run-once step before it starts. *How it is checked:* the route-forwarding bed installs the
authority, the proxy and a consumer from the catalogue and asserts the routed name is served.
### What was built
*2026-08-31.*