ADR 0114: a two-party credential rotates over two logins

Graduates research 016. Retiring a login is separated from removing a
consumer, which closes a data-loss path in five providers; single-party
secrets rotate in place; the number of parties decides, not the provider.
This commit is contained in:
jochen
2026-09-26 00:22:21 +02:00
parent 942ebe350f
commit 43f63ed41c
5 changed files with 234 additions and 20 deletions
@@ -164,10 +164,12 @@ the change using the old value. Where no provisioner can make it, the requiremen
rotatable by the mesh**, and a rotation request is refused, saying why, rather than restarting a service
that would carry on with the old value.
**How old and new change over is not decided here.** Three mechanisms were measured against every
provider's code in [research 016](../01-RESEARCH/016-how-a-credential-can-be-rotated/00-overview.md):
in place, as the controller's `rotate` does today; two secrets on one login; and two logins over one
resource. Its findings bound the choice:
**How old and new change over is decided in [ADR
0114](0114-a-shared-credential-rotates-over-two-logins.md).** Three mechanisms were measured against
every provider's code in [research
016](../01-RESEARCH/016-how-a-credential-can-be-rotated/00-overview.md): in place, as the controller's
`rotate` does today; two secrets on one login; and two logins over one resource. Its findings bound the
choice:
- every credential provider already re-applies a password in place, so today's rotation works, with a
window in which a consumer cannot authenticate;
@@ -178,8 +180,8 @@ resource. Its findings bound the choice:
- every backend can give two logins the same rights over one resource, once the adapter separates the
resource from the login.
The mechanism is decided in its own record, on those facts. Until then rotation stays as the
controller implements it, in place, with its window stated.
On those facts, 0114 rotates a credential two parties hold over two logins, rotates one a single
party holds in place, and separates retiring a login from removing a consumer.
## What this changes in earlier records
@@ -215,7 +217,7 @@ On acceptance, each of these is superseded or amended by this record, not edited
- Resolution expands per-consumer requirements from a provision's contract. The contract declares
them, never the provider's code, so what a provider requires stays predictable from the catalogue.
- A data provider's adapter gains a return value. What a credential provider's adapter must change for
rotation is decided with the mechanism ([research 016](../01-RESEARCH/016-how-a-credential-can-be-rotated/03-the-options.md)).
rotation is [ADR 0114](0114-a-shared-credential-rotates-over-two-logins.md)'s.
- The broker's provisioner gains every bus account, and the controller loses five separate places it
generates a secret today.
- 54 modules move from own secrets to vault requirements. Six provider clients export a password