Accept 0039 — a node owns no password, only an identity

Settled in the operator's own words: nodes should not own passwords, only an
identity when communicating to the broker. Recorded that way at the top of the
record, because it is the whole decision in one line and the rest is why.

What this obliges, in order of newness: enrolment is the one mechanism that does
not exist. Per-node broker users, virtual hosts and per-queue permissions are
broker configuration. Mutual authority is certificates on a connection already
open. And the boundary must fail legibly, which is the requirement the debugging
objection earned.
This commit is contained in:
2026-08-25 23:37:52 +02:00
parent 9ee0c63c7a
commit 66a89cefbe
@@ -1,5 +1,5 @@
---
status: proposed
status: accepted
date: 2026-08-25
deciders: jochen
reconstructed: false
@@ -15,8 +15,11 @@ declarations from, and names the gap it leaves: *"everything a node applies arri
so what may be pushed, and how a joining node proves it is entitled to join, is now a question
worth its own record."*
This is that record. It is a design decision about a boundary that does not exist yet, so it is
proposed rather than measured — but what it replaces is measured, and that is the argument.
This is that record. It is a design decision about a boundary that does not exist yet — but
what it replaces is measured, and that is the argument.
Settled as: **a node owns no password. It owns an identity, and that identity is what it
presents to the broker.**
### What adoption does today