Issue 180: a module's own secret rotates when it is read at start; the applied form stays open (controller PR 183); design 13 and ADR 0114 carry the word

This commit is contained in:
2026-10-01 11:43:23 +02:00
parent 027e5b8d73
commit 48a620249b
3 changed files with 85 additions and 1 deletions
@@ -5,7 +5,7 @@ code:
- mesh-controller internal/inventory/secrets.go
- mesh-controller cmd/mesh-controller/rotate.go
- mesh-controller examples/postgres-provisioner
updated: 2026-09-21
updated: 2026-10-01
decisions:
- 02-DECISIONS/0001-mesh-brokers-nodes-host-agents-think.md
- 02-DECISIONS/0009-modules-and-the-graph.md
@@ -136,3 +136,14 @@ rotates, and is queried for who holds it, through exactly the machinery describe
The rotation a module's own secret lacks is not a second mechanism; it is this one, pointed at a
secret the vault provides. What this page proves for a database password holds, by construction,
for a secret from the vault.
*Built 2026-10-01, the read-at-start half ([issue 180](../../04-ISSUES/180-a-modules-own-secret-cannot-be-rotated/00-report.md),
[ADR 0114](../../02-DECISIONS/0114-a-shared-credential-rotates-over-two-credentials.md)).* An own secret
says how the module takes it — `taken: at-start` or `taken: applied` on its entry — and the mesh
rotates only the first: `secret rotate <node> <module> <name>` makes it anew, seals it to the machine
and the operator, and sends the machine, so the module starts again on it. A secret that says neither
is refused with the word to write, because a credential rotated under software that never reads it
again is the fault of issue 179 made deliberately; an applied one is refused until the staged form is
built; an accepted one is refused as ADR 0113 says. `rotate` is a verb on the controller's seat with
both shapes, so the console asks for either. *How it is checked:* the tests named in issue 180, and a
live rotation through the console of a secret a module reads at start.