The vault shipped: as-is 06 describes it, design 24 is implemented, 071 names its merges

This commit is contained in:
2026-09-21 10:10:33 +02:00
parent aa9b5b99e4
commit 7015bf58ac
4 changed files with 38 additions and 12 deletions
@@ -1,11 +1,12 @@
---
layer: as-is
status: implemented
code: [hal]
updated: 2026-08-23
code: [hal, mesh-controller, mesh-catalog, mesh-host]
updated: 2026-09-21
decisions:
- 02-DECISIONS/0011-managed-files-are-generated-never-edited.md
- 02-DECISIONS/0009-modules-and-the-graph.md
- 02-DECISIONS/0085-a-secret-is-a-provision.md
---
# Configuration and secrets
@@ -73,9 +74,31 @@ when the file is created, so regeneration left the previous mode in place. The c
worth remembering beyond the instance: a permission set at creation is not a permission
maintained.
**Rotation is not a mesh operation.** Secrets can be generated and granted; there is no
mechanism that rotates one and informs everything holding it. Where a rotation has been done,
it has been done by hand, and doing it wrong has taken services down.
**Rotation was not a mesh operation** in the mesh being replaced, and doing it by hand took
services down. On the mesh that exists now it is: `rotate <provision>` discards a pair credential
and delivers both ends in one send, and a module's own secret is such a pair credential when the
module takes it from the vault — which, at the time of writing, one module does (redis).
## The vault, as it runs
Since 2026-09-21 the mesh runs `mesh-vault`, a foundation module installed at genesis beside the
adopted store and broker. It provides `secret`: a module that requires one receives a pair
credential the controller minted, and the vault's ledger records the holder and the value's
fingerprint, notices a rotation, and answers over the mesh by fingerprint only. It holds no value.
Genesis makes the store's superuser and the broker's administrator rather than copying the
template's, keeps them at the paths the store and broker modules declare as their own secrets, and
makes an **operator sealing key** before the first secret is accepted: its private half is a file
beside the produced bundle, which the operator carries off the machine, and its public half is
what the mesh records. Every secret a module holds for itself and every pair credential is sealed
to that key as well as to its node. The export of those copies is written beside the key at the
end of genesis and kept by the vault on its own disk; the operator recovers any secret from it, off
the mesh, with `secret recover`. Secrets made before the key existed, or sealed to a replaced key,
are listed as such rather than passed off as recoverable. The produced bundle and the installer's
transcript carry no credential in the clear.
Two things this does not yet do: a module with several own secrets cannot take them all from the
vault (issue 069), and an operator cannot hand a value into a pair credential (issue 070).
## Node-level and mesh-level values