ADR 0112: a module's own secrets are a provision from the vault, not something the mesh generates

The first draft listed minted secrets under what the mesh generates. ADR 0085 made a module's own
secret — a password, an internal token, an external key it was handed — a secret provision answered
by the vault, like a database by the store. What the mesh still mints is the delivery credential for
each provision a module takes (ADR 0048), the vault's own included.
This commit is contained in:
jochen
2026-09-25 22:29:38 +02:00
parent ca235e775f
commit 90fb7ae4ad
@@ -56,12 +56,16 @@ unresolved variable and what could answer it. Variables are answered from three
settings ([ADR 0046](0046-a-module-configuration-is-its-assignments-not-its-manifest.md)). An settings ([ADR 0046](0046-a-module-configuration-is-its-assignments-not-its-manifest.md)). An
endpoint binding a public name to a port is one. endpoint binding a public name to a port is one.
2. **Provisions, resolved by the mesh against a contract.** A database, a bucket, a vhost, the 2. **Provisions, resolved by the mesh against a contract.** A database, a bucket, a vhost, the
occupant of a seat, another assignment: each with the contract the mesh and the module's occupant of a seat, another assignment, and **a secret from the vault**: a module's own
specification define. Which node answers one is part of the assignment password, internal token or external key is a `secret` provision like any other
([ADR 0085](0085-a-secret-is-a-provision.md)). Each comes with the contract the mesh and the
module's specification define. Which node answers one is part of the assignment
([ADR 0084](0084-which-provider-serves-a-consumer.md)), so a module may take its database from ([ADR 0084](0084-which-provider-serves-a-consumer.md)), so a module may take its database from
another node. another node.
3. **What the mesh generates or knows.** Minted secrets, the ports it assigns 3. **What the mesh generates or knows.** The credential it mints for each provision a module
([ADR 0038](0038-the-mesh-assigns-the-port.md)), facts about the machine. takes, which is how every provision is delivered, the vault's included
([ADR 0048](0048-a-provider-creates-the-credential-the-mesh-minted.md)); the ports it assigns
([ADR 0038](0038-the-mesh-assigns-the-port.md)); facts about the machine.
**A directory is a provision.** A module requires one by name, such as its configuration or its **A directory is a provision.** A module requires one by name, such as its configuration or its
data, and the host on the node where the assignment runs answers it. Its contract is what the data, and the host on the node where the assignment runs answers it. Its contract is what the
@@ -125,5 +129,7 @@ configuration colliding: a public name already taken is refused like any other s
- [ADR 0038](0038-the-mesh-assigns-the-port.md): the same decision, for ports - [ADR 0038](0038-the-mesh-assigns-the-port.md): the same decision, for ports
- [ADR 0046](0046-a-module-configuration-is-its-assignments-not-its-manifest.md): configuration is the assignment's - [ADR 0046](0046-a-module-configuration-is-its-assignments-not-its-manifest.md): configuration is the assignment's
- [ADR 0084](0084-which-provider-serves-a-consumer.md): which node answers is the assignment's - [ADR 0084](0084-which-provider-serves-a-consumer.md): which node answers is the assignment's
- [ADR 0085](0085-a-secret-is-a-provision.md), [ADR 0048](0048-a-provider-creates-the-credential-the-mesh-minted.md):
a module's own secrets come from the vault; the mesh mints only the delivery credential
- [ADR 0051](0051-shared-data-is-the-operators.md), [ADR 0107](0107-persistent-data-is-a-directory-bind-never-a-named-volume.md), - [ADR 0051](0051-shared-data-is-the-operators.md), [ADR 0107](0107-persistent-data-is-a-directory-bind-never-a-named-volume.md),
[ADR 0030](0030-data-outlives-the-mesh-that-declared-it.md): what a directory's contract carries [ADR 0030](0030-data-outlives-the-mesh-that-declared-it.md): what a directory's contract carries