Accept 0039 — a node owns no password, only an identity
Settled in the operator's own words: nodes should not own passwords, only an identity when communicating to the broker. Recorded that way at the top of the record, because it is the whole decision in one line and the rest is why. What this obliges, in order of newness: enrolment is the one mechanism that does not exist. Per-node broker users, virtual hosts and per-queue permissions are broker configuration. Mutual authority is certificates on a connection already open. And the boundary must fail legibly, which is the requirement the debugging objection earned.
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
---
|
||||
status: proposed
|
||||
status: accepted
|
||||
date: 2026-08-25
|
||||
deciders: jochen
|
||||
reconstructed: false
|
||||
@@ -15,8 +15,11 @@ declarations from, and names the gap it leaves: *"everything a node applies arri
|
||||
so what may be pushed, and how a joining node proves it is entitled to join, is now a question
|
||||
worth its own record."*
|
||||
|
||||
This is that record. It is a design decision about a boundary that does not exist yet, so it is
|
||||
proposed rather than measured — but what it replaces is measured, and that is the argument.
|
||||
This is that record. It is a design decision about a boundary that does not exist yet — but
|
||||
what it replaces is measured, and that is the argument.
|
||||
|
||||
Settled as: **a node owns no password. It owns an identity, and that identity is what it
|
||||
presents to the broker.**
|
||||
|
||||
### What adoption does today
|
||||
|
||||
|
||||
Reference in New Issue
Block a user