From b68103d198d01a42370b8b616dac4ab12097f4c0 Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 31 Aug 2026 21:31:26 +0200 Subject: [PATCH] A module is adopted with the credentials it already has MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Nothing is rotated during the conversion. A service keeps the password it is already using, because minting a new one is how a running service stops being able to reach its own database mid-migration. The mesh has both paths already: generate-and-seal for a new module, accept-and-seal for an adopted one. Adoption needs the second, and it is built. Rotation becomes a separate act afterwards, once everything works — the machinery is proven, and it is a thing to do deliberately rather than as a side effect of moving a service between systems. Records the step that has to come first and is easy to miss: read the current environment out of the old system while it can still be read. Once accepted, the mesh cannot show a secret back, and once the old system is gone neither can that. A password nobody wrote down is a service nobody can adopt. --- 03-DESIGN/01-to-be/00-work-breakdown.md | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) diff --git a/03-DESIGN/01-to-be/00-work-breakdown.md b/03-DESIGN/01-to-be/00-work-breakdown.md index cf61b0b..6d77bd1 100644 --- a/03-DESIGN/01-to-be/00-work-breakdown.md +++ b/03-DESIGN/01-to-be/00-work-breakdown.md @@ -133,6 +133,29 @@ nothing about a disk, a mistaken command, or a service corrupting its own store. through the service that owns it, and only then does anything point at the new location. Never moved and then checked. **A backup nobody has restored is a belief, not a copy.** +## A module is adopted with the credentials it already has + +*2026-08-31.* **Nothing is rotated during the conversion.** A service being adopted keeps the +password it is already using, because minting a new one is how a running service stops being able +to reach its own database in the middle of a migration. + +The mesh has both paths and this needs the second: + +| | | +|---|---| +| **generate** | a new secret, sealed to both ends. What a *new* module gets | +| **accept** | a value supplied from outside, sealed, plaintext discarded. **What an adopted module gets** | + +**Rotation is a separate act, afterwards, once everything works.** The machinery for it is built +and proven — a credential moving at both ends with the old one ceasing to work — and it is exactly +the sort of thing to do deliberately on a quiet afternoon rather than as a side effect of moving a +service between systems. + +**So there is a step before any of this: read the current environment out of the old system while +it can still be read.** Once a value is accepted, the mesh cannot show it back — *a mesh that can +reveal a secret is a mesh that holds it* — and once the old system is gone, neither can that. A +password nobody wrote down is a service nobody can adopt. + ## Where it starts, and what that costs **On the node holding all the production data**, because that is where the services being