Issue 076 opened: a served fact made at first start cannot be served; ADR 0097's refusal of an undeclared base is live

This commit is contained in:
2026-09-21 22:16:15 +02:00
parent 559683318b
commit bc373797c7
4 changed files with 52 additions and 6 deletions
@@ -27,3 +27,6 @@ sidecar beds proved a sidecar alone, which the module beds prove whole; the mini
grant beds proved a grant with a second store beside the foundation's, which the grant bed and
the vault bed prove against the catalogue. Retired, with their scenarios. Two remain declared:
route-forwarding, which needs the certificate authority beside the proxy, and the large mesh test.
*Route-forwarding's conversion is blocked:* the catalogue's authority cannot be raised as written
([issue 076](../076-a-served-fact-made-at-first-start-cannot-be-served/00-report.md)).
@@ -0,0 +1,42 @@
---
status: located
opened: 2026-09-21
located-in: [mesh-catalog modules/step-ca, mesh-controller internal/catalogue (serves)]
fixed-by:
amended-design:
---
# A served fact made at first start cannot be served, so the catalogue's authority cannot start
## Symptom, as observed
The catalogue's certificate authority module declares its root certificate, its root key and
that key's password as its own secrets, and writes each into a file the container is told to
initialise from. The mesh mints an own secret as random bytes. Random bytes are not a
certificate: as written, the authority cannot initialise, and no bed has ever raised it — the
whole-mesh bed that names it has not run since it was converted. Found while converting the
route-forwarding bed to the catalogue's proxy, which requires the authority beside it.
The authority can make its own root at first start — the certificate bed raises it that way and
it issues within a second. What it cannot do then is tell the mesh what that root is: a
consumer of `acme-ca` is given `${bound:acme-ca:root}` from the provider's `serves`, which is
written in the manifest before anything runs.
## Why it matters beyond this instance
- **Two kinds of secret the vocabulary does not distinguish.** A value the mesh may invent (a
password) and a value only the module can produce (a key pair, a certificate) are both
"own secrets", and the mesh invents both.
- **A served fact that exists only after first start** has no way into a binding. Anything a
module generates and its consumers must trust — a root, a public key, a fingerprint — is in
the same position.
- Every consumer of `acme-ca`, which today is the route proxy, is blocked with it.
## What would close it
Either a module may say a secret is *made by the module* — the mesh reserves the name, the
module writes the value once, the mesh takes custody of it and delivers it where it is bound —
or a served fact may be *contributed at run time* by the provider's runtime rather than written
in its manifest. The first is the smaller change and covers the root certificate; the second is
what a fingerprint or a public key wants. Decided, then the authority raised in the lab beside
the proxy, which is the route-forwarding bed's conversion.