Apply review: two credentials, staged admin rotation, a ninth provider
The fact-check found mailu, whose user is its mailbox, so 0114 rotates over two credentials rather than two logins, the adapter choosing what a credential is. Also: minio keeps non-empty buckets; five backends take their admin credential only at first init, so single-party rotation is staged; postgres ownership moves to a non-login role; the harness keys by consumer; rotation state lives with the vault. Consistency fixes across 0110-0113, 26 and 27; issue 103 resolved by mesh-host PR #22.
This commit is contained in:
+2
-2
@@ -1,8 +1,8 @@
|
||||
---
|
||||
status: located
|
||||
status: resolved
|
||||
opened: 2026-09-23
|
||||
located-in: [mesh-host internal/apply]
|
||||
fixed-by:
|
||||
fixed-by: mesh-host PR #22 — a container records the digest of every file it reads at creation, its env-files and files mounted into it directly, and is recreated when one changes; a mounted directory still needs restart-on
|
||||
amended-design:
|
||||
---
|
||||
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
---
|
||||
status: open
|
||||
status: located
|
||||
opened: 2026-09-25
|
||||
located-in: []
|
||||
located-in: [mesh-catalog modules, mesh-controller internal/catalogue]
|
||||
fixed-by:
|
||||
amended-design:
|
||||
---
|
||||
@@ -60,6 +60,11 @@ module to one node would share every one of them. Assigning the same application
|
||||
ordinary need: production beside staging, one site per customer, two instances of one service
|
||||
configured differently, two stores of one engine.
|
||||
|
||||
[ADR 0112](../../02-DECISIONS/0112-a-module-definition-names-no-node-mesh-or-path.md), which answers
|
||||
this report, declines that need rather than meeting it. A module is assigned at most once to a node,
|
||||
because every identity in the mesh is already a module on a node. The cases above become different
|
||||
modules, or the same module on different machines.
|
||||
|
||||
## Why it matters beyond this instance
|
||||
|
||||
A definition that names machine paths is not portable between nodes. It cannot follow data onto a
|
||||
|
||||
Reference in New Issue
Block a user