The vault shipped: as-is 06 describes it, design 24 is implemented, 071 names its merges

This commit is contained in:
2026-09-21 10:10:33 +02:00
parent aa9b5b99e4
commit 7015bf58ac
4 changed files with 38 additions and 12 deletions
@@ -1,11 +1,12 @@
--- ---
layer: as-is layer: as-is
status: implemented status: implemented
code: [hal] code: [hal, mesh-controller, mesh-catalog, mesh-host]
updated: 2026-08-23 updated: 2026-09-21
decisions: decisions:
- 02-DECISIONS/0011-managed-files-are-generated-never-edited.md - 02-DECISIONS/0011-managed-files-are-generated-never-edited.md
- 02-DECISIONS/0009-modules-and-the-graph.md - 02-DECISIONS/0009-modules-and-the-graph.md
- 02-DECISIONS/0085-a-secret-is-a-provision.md
--- ---
# Configuration and secrets # Configuration and secrets
@@ -73,9 +74,31 @@ when the file is created, so regeneration left the previous mode in place. The c
worth remembering beyond the instance: a permission set at creation is not a permission worth remembering beyond the instance: a permission set at creation is not a permission
maintained. maintained.
**Rotation is not a mesh operation.** Secrets can be generated and granted; there is no **Rotation was not a mesh operation** in the mesh being replaced, and doing it by hand took
mechanism that rotates one and informs everything holding it. Where a rotation has been done, services down. On the mesh that exists now it is: `rotate <provision>` discards a pair credential
it has been done by hand, and doing it wrong has taken services down. and delivers both ends in one send, and a module's own secret is such a pair credential when the
module takes it from the vault — which, at the time of writing, one module does (redis).
## The vault, as it runs
Since 2026-09-21 the mesh runs `mesh-vault`, a foundation module installed at genesis beside the
adopted store and broker. It provides `secret`: a module that requires one receives a pair
credential the controller minted, and the vault's ledger records the holder and the value's
fingerprint, notices a rotation, and answers over the mesh by fingerprint only. It holds no value.
Genesis makes the store's superuser and the broker's administrator rather than copying the
template's, keeps them at the paths the store and broker modules declare as their own secrets, and
makes an **operator sealing key** before the first secret is accepted: its private half is a file
beside the produced bundle, which the operator carries off the machine, and its public half is
what the mesh records. Every secret a module holds for itself and every pair credential is sealed
to that key as well as to its node. The export of those copies is written beside the key at the
end of genesis and kept by the vault on its own disk; the operator recovers any secret from it, off
the mesh, with `secret recover`. Secrets made before the key existed, or sealed to a replaced key,
are listed as such rather than passed off as recoverable. The produced bundle and the installer's
transcript carry no credential in the clear.
Two things this does not yet do: a module with several own secrets cannot take them all from the
vault (issue 069), and an operator cannot hand a value into a pair credential (issue 070).
## Node-level and mesh-level values ## Node-level and mesh-level values
+3
View File
@@ -5,6 +5,9 @@ code:
- mesh-host examples/foundation-first-node.lock - mesh-host examples/foundation-first-node.lock
- mesh-host internal/apply - mesh-host internal/apply
- mesh-host internal/bootstrap/phase3.go - mesh-host internal/bootstrap/phase3.go
- mesh-host internal/bootstrap/rootsecrets.go
- mesh-host internal/bootstrap/operator.go
- mesh-catalog modules/mesh-vault
- mesh-catalog modules/postgres - mesh-catalog modules/postgres
- mesh-catalog modules/lavinmq - mesh-catalog modules/lavinmq
- mesh-lab test/integration/mesh.test.ts (a bare machine becomes a mesh) - mesh-lab test/integration/mesh.test.ts (a bare machine becomes a mesh)
+6 -6
View File
@@ -1,8 +1,8 @@
--- ---
layer: to-be layer: to-be
status: in-progress status: implemented
code: [mesh-catalog, mesh-controller] code: [mesh-catalog, mesh-controller, mesh-host]
updated: 2026-09-20 updated: 2026-09-21
decisions: decisions:
- 02-DECISIONS/0085-a-secret-is-a-provision.md - 02-DECISIONS/0085-a-secret-is-a-provision.md
- 02-DECISIONS/0031-the-control-plane-authenticates-nobody.md - 02-DECISIONS/0031-the-control-plane-authenticates-nobody.md
@@ -106,9 +106,9 @@ The vault's second job is to hold these, and it does so without holding a value:
answered by it. answered by it.
**Genesis** makes the operator key first and mints real root secrets in place of the fixed ones the **Genesis** makes the operator key first and mints real root secrets in place of the fixed ones the
foundation is raised with, so the mesh is handed over with nothing well-known in it. That step is foundation is raised with, so the mesh is handed over with nothing well-known in it. The installer
the installer's and is not yet built; until it is, the fixed credentials are the as-is and are does this ([21](21-the-installation-in-full.md)); what it runs is described in the as-is
said so in [21](21-the-installation-in-full.md). ([`00-as-is/06`](../00-as-is/06-configuration-and-secrets.md)).
A module's vault-provided secret — the pair credential of A module's vault-provided secret — the pair credential of
[13](13-credentials-and-their-rotation.md) — is sealed to the operator the same way, as is every [13](13-credentials-and-their-rotation.md) — is sealed to the operator the same way, as is every
@@ -2,7 +2,7 @@
status: resolved status: resolved
opened: 2026-09-20 opened: 2026-09-20
located-in: [mesh-host internal/bootstrap, mesh-host examples/foundation-first-node.lock] located-in: [mesh-host internal/bootstrap, mesh-host examples/foundation-first-node.lock]
fixed-by: mesh-host feat/secrets-vault (ee0c8b8, genesis root credentials + operator key + vault); mesh-controller feat/secrets-vault (e140ed5, 565f144); mesh-catalog feat/secrets-vault; proven by the one-node genesis bed step V5 fixed-by: mesh-host PR 14 (e30a6b0), mesh-controller PR 34 (6b695c8), mesh-catalog PR 30 (d03520f), mesh-lab PR 39 (7e2e97f); proven by the one-node genesis bed step V5, 22/22
amended-design: 03-DESIGN/01-to-be/24-the-secrets-vault.md amended-design: 03-DESIGN/01-to-be/24-the-secrets-vault.md
--- ---