diff --git a/04-ISSUES/180-a-modules-own-secret-cannot-be-rotated/00-report.md b/04-ISSUES/180-a-modules-own-secret-cannot-be-rotated/00-report.md index 07ef9fa..5b91167 100644 --- a/04-ISSUES/180-a-modules-own-secret-cannot-be-rotated/00-report.md +++ b/04-ISSUES/180-a-modules-own-secret-cannot-be-rotated/00-report.md @@ -55,6 +55,17 @@ rotates a secret taken at start, refuses an applied one, an undeclared one, an a unknown name, each in its own words; the verb's two shapes; and, live, a secret rotated through the console on a module that reads it at start, the module restarted, and the module working. +*Done live, 2026-10-01 10:13 UTC:* the search module on the home server, the first definition to say +`taken: at-start` whose value the mesh had made. Asked through the console; the controller said it was +rotated and sent the machine; twenty-seven seconds later the secret file carried a new write time, the +server container had restarted on it, and the module answered. The two secrets filed in the forge's +report, the automation module's token and admin password, were refused: both had been accepted by hand +during adoption, and that refusal is the one ADR 0113 asks for — something outside the mesh may hold +an accepted value, so replacing it is a person's act. Modules whose source is pinned to a commit are +not rebuilt by a merge; their new definition was registered by asking for a build of main through the +console, which since [issue 176](../176-the-consoles-build-tool-neither-waits-nor-registers/00-report.md) +registers what it hears. + ## Open — the applied form The staged rotation ADR 0114 decided for an applied secret is not built: the vault delivering the