ADR 0112: a module's own secrets are a provision from the vault, not something the mesh generates
The first draft listed minted secrets under what the mesh generates. ADR 0085 made a module's own secret — a password, an internal token, an external key it was handed — a secret provision answered by the vault, like a database by the store. What the mesh still mints is the delivery credential for each provision a module takes (ADR 0048), the vault's own included.
This commit is contained in:
@@ -56,12 +56,16 @@ unresolved variable and what could answer it. Variables are answered from three
|
|||||||
settings ([ADR 0046](0046-a-module-configuration-is-its-assignments-not-its-manifest.md)). An
|
settings ([ADR 0046](0046-a-module-configuration-is-its-assignments-not-its-manifest.md)). An
|
||||||
endpoint binding a public name to a port is one.
|
endpoint binding a public name to a port is one.
|
||||||
2. **Provisions, resolved by the mesh against a contract.** A database, a bucket, a vhost, the
|
2. **Provisions, resolved by the mesh against a contract.** A database, a bucket, a vhost, the
|
||||||
occupant of a seat, another assignment: each with the contract the mesh and the module's
|
occupant of a seat, another assignment, and **a secret from the vault**: a module's own
|
||||||
specification define. Which node answers one is part of the assignment
|
password, internal token or external key is a `secret` provision like any other
|
||||||
|
([ADR 0085](0085-a-secret-is-a-provision.md)). Each comes with the contract the mesh and the
|
||||||
|
module's specification define. Which node answers one is part of the assignment
|
||||||
([ADR 0084](0084-which-provider-serves-a-consumer.md)), so a module may take its database from
|
([ADR 0084](0084-which-provider-serves-a-consumer.md)), so a module may take its database from
|
||||||
another node.
|
another node.
|
||||||
3. **What the mesh generates or knows.** Minted secrets, the ports it assigns
|
3. **What the mesh generates or knows.** The credential it mints for each provision a module
|
||||||
([ADR 0038](0038-the-mesh-assigns-the-port.md)), facts about the machine.
|
takes, which is how every provision is delivered, the vault's included
|
||||||
|
([ADR 0048](0048-a-provider-creates-the-credential-the-mesh-minted.md)); the ports it assigns
|
||||||
|
([ADR 0038](0038-the-mesh-assigns-the-port.md)); facts about the machine.
|
||||||
|
|
||||||
**A directory is a provision.** A module requires one by name, such as its configuration or its
|
**A directory is a provision.** A module requires one by name, such as its configuration or its
|
||||||
data, and the host on the node where the assignment runs answers it. Its contract is what the
|
data, and the host on the node where the assignment runs answers it. Its contract is what the
|
||||||
@@ -125,5 +129,7 @@ configuration colliding: a public name already taken is refused like any other s
|
|||||||
- [ADR 0038](0038-the-mesh-assigns-the-port.md): the same decision, for ports
|
- [ADR 0038](0038-the-mesh-assigns-the-port.md): the same decision, for ports
|
||||||
- [ADR 0046](0046-a-module-configuration-is-its-assignments-not-its-manifest.md): configuration is the assignment's
|
- [ADR 0046](0046-a-module-configuration-is-its-assignments-not-its-manifest.md): configuration is the assignment's
|
||||||
- [ADR 0084](0084-which-provider-serves-a-consumer.md): which node answers is the assignment's
|
- [ADR 0084](0084-which-provider-serves-a-consumer.md): which node answers is the assignment's
|
||||||
|
- [ADR 0085](0085-a-secret-is-a-provision.md), [ADR 0048](0048-a-provider-creates-the-credential-the-mesh-minted.md):
|
||||||
|
a module's own secrets come from the vault; the mesh mints only the delivery credential
|
||||||
- [ADR 0051](0051-shared-data-is-the-operators.md), [ADR 0107](0107-persistent-data-is-a-directory-bind-never-a-named-volume.md),
|
- [ADR 0051](0051-shared-data-is-the-operators.md), [ADR 0107](0107-persistent-data-is-a-directory-bind-never-a-named-volume.md),
|
||||||
[ADR 0030](0030-data-outlives-the-mesh-that-declared-it.md): what a directory's contract carries
|
[ADR 0030](0030-data-outlives-the-mesh-that-declared-it.md): what a directory's contract carries
|
||||||
|
|||||||
Reference in New Issue
Block a user