Amend ADR 0085: the vault is a foundation module and holds the root secrets

Recorded on the record, dated, before anything shipped against the sentences
that change. The vault is installed at genesis like the store and broker, one
per mesh, and holds every secret a module has for itself sealed a second time
to an operator key whose private half never enters the mesh — the break-glass
path the first version left open, without a key one place holds.

Design 24 says how; 07 and 21 say what genesis does not yet do; issue 071
names the fixed credentials the foundation is raised with today.
This commit is contained in:
2026-09-20 23:55:01 +02:00
parent 187389b7d1
commit baa3351552
5 changed files with 154 additions and 22 deletions
+6
View File
@@ -246,6 +246,12 @@ host's vocabulary grows by one shape rather than by one resource type per founda
the module that provides one.
- **Whether one host can raise all three.** The claim under stage 2 of
[the node host](05-the-node-host.md), never proved. If it is false, the tier boundary moves.
- **The vault as the fourth piece.** [ADR 0085](../../02-DECISIONS/0085-a-secret-is-a-provision.md),
amended, makes the vault a foundation module: genesis makes the operator key before anything
is minted, replaces the fixed credentials the store and broker are raised with, and installs
`mesh-vault` beside the adopted store and broker ([24](24-the-secrets-vault.md)). The controller's
half exists; the installer's does not yet, and the bundle still raises the foundation with
well-known credentials ([issue 071](../../04-ISSUES/071-the-foundation-is-raised-with-fixed-credentials/00-report.md)).
- **How the foundation is updated once a mesh exists.** Pinned by hand at bootstrap; afterwards
the controller could deliver it like anything else, and nothing says whether it does.