From 90fb7ae4ada35d38229c1bd34db66c682c704615 Mon Sep 17 00:00:00 2001 From: jochen Date: Fri, 25 Sep 2026 22:13:37 +0200 Subject: [PATCH] ADR 0112: a module's own secrets are a provision from the vault, not something the mesh generates MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The first draft listed minted secrets under what the mesh generates. ADR 0085 made a module's own secret — a password, an internal token, an external key it was handed — a secret provision answered by the vault, like a database by the store. What the mesh still mints is the delivery credential for each provision a module takes (ADR 0048), the vault's own included. --- ...module-definition-names-no-node-mesh-or-path.md | 14 ++++++++++---- 1 file changed, 10 insertions(+), 4 deletions(-) diff --git a/02-DECISIONS/0112-a-module-definition-names-no-node-mesh-or-path.md b/02-DECISIONS/0112-a-module-definition-names-no-node-mesh-or-path.md index 0d664f9..da9bed4 100644 --- a/02-DECISIONS/0112-a-module-definition-names-no-node-mesh-or-path.md +++ b/02-DECISIONS/0112-a-module-definition-names-no-node-mesh-or-path.md @@ -56,12 +56,16 @@ unresolved variable and what could answer it. Variables are answered from three settings ([ADR 0046](0046-a-module-configuration-is-its-assignments-not-its-manifest.md)). An endpoint binding a public name to a port is one. 2. **Provisions, resolved by the mesh against a contract.** A database, a bucket, a vhost, the - occupant of a seat, another assignment: each with the contract the mesh and the module's - specification define. Which node answers one is part of the assignment + occupant of a seat, another assignment, and **a secret from the vault**: a module's own + password, internal token or external key is a `secret` provision like any other + ([ADR 0085](0085-a-secret-is-a-provision.md)). Each comes with the contract the mesh and the + module's specification define. Which node answers one is part of the assignment ([ADR 0084](0084-which-provider-serves-a-consumer.md)), so a module may take its database from another node. -3. **What the mesh generates or knows.** Minted secrets, the ports it assigns - ([ADR 0038](0038-the-mesh-assigns-the-port.md)), facts about the machine. +3. **What the mesh generates or knows.** The credential it mints for each provision a module + takes, which is how every provision is delivered, the vault's included + ([ADR 0048](0048-a-provider-creates-the-credential-the-mesh-minted.md)); the ports it assigns + ([ADR 0038](0038-the-mesh-assigns-the-port.md)); facts about the machine. **A directory is a provision.** A module requires one by name, such as its configuration or its data, and the host on the node where the assignment runs answers it. Its contract is what the @@ -125,5 +129,7 @@ configuration colliding: a public name already taken is refused like any other s - [ADR 0038](0038-the-mesh-assigns-the-port.md): the same decision, for ports - [ADR 0046](0046-a-module-configuration-is-its-assignments-not-its-manifest.md): configuration is the assignment's - [ADR 0084](0084-which-provider-serves-a-consumer.md): which node answers is the assignment's +- [ADR 0085](0085-a-secret-is-a-provision.md), [ADR 0048](0048-a-provider-creates-the-credential-the-mesh-minted.md): + a module's own secrets come from the vault; the mesh mints only the delivery credential - [ADR 0051](0051-shared-data-is-the-operators.md), [ADR 0107](0107-persistent-data-is-a-directory-bind-never-a-named-volume.md), [ADR 0030](0030-data-outlives-the-mesh-that-declared-it.md): what a directory's contract carries