ADR 0094: a module may hold several secrets from one provider; issue 069 resolved; design 24 amended

This commit is contained in:
2026-09-21 20:29:29 +02:00
parent a259d1292f
commit acc9824949
5 changed files with 78 additions and 8 deletions
@@ -1,9 +1,9 @@
---
status: located
status: resolved
opened: 2026-09-20
located-in: [mesh-controller internal/catalogue (requires/secrets), mesh-controller internal/inventory (secret key)]
fixed-by:
amended-design:
fixed-by: ADR 0094; mesh-controller feat/several-secrets (secrets: under local names, the pair keyed on the local name, migration 0027); proven by the vault bed
amended-design: 03-DESIGN/01-to-be/24-the-secrets-vault.md
---
# One `secret` provision yields one value, and a module may need several
@@ -18,6 +18,7 @@
is a manifest-vocabulary decision, and it moves the pair key: the credential must be keyed on
the local name, not the provision name, or the second pair overwrites the first.
**Located in:** the manifest's `requires`/`secrets` vocabulary (the catalogue parser) and the pair
credential's key (the controller's secret store). Not fixed here: the key change touches every
existing pair and belongs in a feature of its own, with a lab run against the vault bed.
**Located in:** the manifest's `secrets` vocabulary (the catalogue parser) and the pair
credential's key (the controller's secret store). Fixed as
[ADR 0094](../../02-DECISIONS/0094-a-module-may-hold-several-secrets-from-one-provider.md): the
key gains the local name, empty for every existing pair, so nothing that exists changed.