Review corrections: 076 and ADR 0098 say what the authority could and could not do; issues 077 (a fetched fact is fetched once) and 078 (secret accept takes any name) opened

This commit is contained in:
2026-09-21 22:55:11 +02:00
parent 6d3cb60949
commit 6bc9df4b49
6 changed files with 93 additions and 13 deletions
@@ -13,8 +13,8 @@ extends: 02-DECISIONS/0085-a-secret-is-a-provision.md
The catalogue's certificate authority declared its root certificate, its root key and that key's
password as its own secrets, and told the container to initialise from them. The mesh mints an
own secret as random bytes, and random bytes are not a certificate: as written the authority
could not start, and no bed had raised it
own secret nobody delivers as random bytes, and random bytes are not a certificate: issued, the
authority could not start; only an operator hand-making its root could raise it
([issue 076](../04-ISSUES/076-a-served-fact-made-at-first-start-cannot-be-served/00-report.md)).
The authority can make its own root at first start. What it could not do then was tell the mesh
what that root is: a consumer was given `${bound:acme-ca:root}` from the provider's `serves`,
@@ -48,8 +48,11 @@ a fact that changes after first start is refetched only when the declaration cha
## How it is checked
The route-forwarding bed installs the authority, the proxy and a consumer from the catalogue and
asserts a routed name is served through the proxy; the proxy cannot start without the root its
gate fetched. The catalogue-wide manifest test parses both manifests.
asserts a routed name is served through the proxy. The proxy refuses to start on a bundle that is
not a certificate, so the name being served proves the gate fetched one; the gate itself refuses
a body that is not a certificate. That the proxy obtains a certificate from this authority through
that root is the certificate bed's proof, against the same authority with the same proxy. The
catalogue-wide manifest test parses both manifests.
## References