ADR 0158: a provider with one credential shares it with every consumer, and the vault remakes it for all at once; designs 24 and 13 carry it

This commit is contained in:
2026-10-01 12:17:49 +02:00
parent d85b41ae4d
commit d29d3dfc23
4 changed files with 134 additions and 2 deletions
@@ -145,5 +145,7 @@ and the operator, and sends the machine, so the module starts again on it. A sec
is refused with the word to write, because a credential rotated under software that never reads it
again is the fault of issue 179 made deliberately; an applied one is refused until the staged form is
built; an accepted one is refused as ADR 0113 says. `rotate` is a verb on the controller's seat with
both shapes, so the console asks for either. *How it is checked:* the tests named in issue 180, and a
both shapes, so the console asks for either. A provider that shares its one credential with every
consumer ([ADR 0158](../../02-DECISIONS/0158-a-provider-with-one-credential-shares-it-with-every-consumer.md))
rotates the same way, with every holder's copy remade and every holding machine sent together. *How it is checked:* the tests named in issue 180, and a
live rotation through the console of a secret a module reads at start.
+18 -1
View File
@@ -2,8 +2,9 @@
layer: to-be
status: implemented
code: [mesh-catalog, mesh-controller, mesh-host]
updated: 2026-09-21
updated: 2026-10-01
decisions:
- 02-DECISIONS/0158-a-provider-with-one-credential-shares-it-with-every-consumer.md
- 02-DECISIONS/0094-a-module-may-hold-several-secrets-from-one-provider.md
- 02-DECISIONS/0092-an-operator-delivers-a-pair-credential.md
- 02-DECISIONS/0085-a-secret-is-a-provision.md
@@ -127,6 +128,22 @@ credential a provider grants; the export names each entry by the node and module
the name they know it by, and says whether it is a module's own secret or a pair credential, so
recovery addresses both alike.
### A provider with one credential
*Decided 2026-10-01 ([ADR 0158](../../02-DECISIONS/0158-a-provider-with-one-credential-shares-it-with-every-consumer.md)); to be built.*
Software that holds one credential — a download client's web password, an indexer's one API key —
cannot give each consumer a login, so ADR 0048's form does not fit it and its values were accepted
by hand. An offer may now say `"credential": {"own": "<secret>"}`: the provider's own secret *is* the
credential every consumer of that provision receives, in the shape of an ordinary pair credential,
under the provider's one user name. The vault keeps one value per provider assignment and provision,
sealed to the provider's machine, each consumer's machine and the operator; because it holds no
plaintext it remakes the value for every holder at once when a consumer binds or unbinds or a
rotation is asked, and the mesh sends every holding machine together. The provider takes it as it
says it takes its own secret (`taken`, issue 180); consumers read it at start. An accepted value is
sealed to the consumers of the moment and not remade; a consumer that binds later waits for the next
acceptance. *How it is checked:* the rows of ADR 0158's table, once built.
## Beyond generate and hold
Owning a secret means owning more than its creation. The mesh being migrated onto has a working