Amend ADR 0085: the vault is a foundation module and holds the root secrets

Recorded on the record, dated, before anything shipped against the sentences
that change. The vault is installed at genesis like the store and broker, one
per mesh, and holds every secret a module has for itself sealed a second time
to an operator key whose private half never enters the mesh — the break-glass
path the first version left open, without a key one place holds.

Design 24 says how; 07 and 21 say what genesis does not yet do; issue 071
names the fixed credentials the foundation is raised with today.
This commit is contained in:
2026-09-20 23:55:01 +02:00
parent 187389b7d1
commit baa3351552
5 changed files with 154 additions and 22 deletions
@@ -0,0 +1,39 @@
---
status: located
opened: 2026-09-20
located-in: [mesh-host internal/bootstrap, mesh-host examples/foundation-first-node.lock]
fixed-by:
amended-design: 03-DESIGN/01-to-be/24-the-secrets-vault.md
---
# The foundation is raised with fixed credentials, and they stay
## Symptom, as observed
The foundation bundle raises the store with a superuser password that is the literal word
`bootstrap`, and the broker with its image's default administrator, `guest` / `guest`. The
installer then carries both into the mesh through `secret accept`, sealed to the control-node's
key, marked `accepted` so the mesh will never replace them — which is correct for a credential
that already created the databases, and means the well-known value is now permanent.
Every module's own secret minted afterwards is random and sealed. The two that everything else
rests on are not random, and there is no operator key at genesis for anything to be sealed to.
## Why it matters beyond this instance
- **These are the root secrets.** A mesh whose store superuser is a published constant is a mesh
whose every provisioned credential is one connection away, from any node that can reach 5432.
- **It is invisible.** `secret accept` reports the value as sealed to the machine and unreadable by
the mesh, which is true, and says nothing about where it came from.
- **Rotation cannot fix it later.** An accepted own secret is never remade by the mesh, and there is
no `rotate` for own secrets; the only path is to change it on the server by hand and accept it
again, which is the manual rotation the as-is design records as having taken services down.
## What closes it
[ADR 0085](../../02-DECISIONS/0085-a-secret-is-a-provision.md), amended, and design
[24](../../03-DESIGN/01-to-be/24-the-secrets-vault.md): genesis makes the operator key first,
mints real credentials for the store and broker before the bundle raises them (or changes them
on the running servers before handing over), accepts those, and installs `mesh-vault` so the
operator-sealed export exists from the first push. The controller's half — the key, the second
seal, export and recovery — is built; the installer's half is not.