The control plane authenticates nobody, so identity is a module
Closes the last open question about what the substrate contains. 0006 left an identity provider conditional — substrate only if the control plane delegated authentication — and said the decision had not been taken. It is now: it delegates to nothing. The conditional was never about machines. A node proves itself with a keypair it generated over a broker account issued at enrolment, and declarations are verified by signature; none of that involves an identity provider. It was only ever about whether a person signing in to a mesh surface would be authenticated by something else. So the substrate is three — a relational store, a message bus, an image registry — and with 0028 having removed the object store, no member is conditional and every one is there for the same reason. It does not settle how a person signs in to a surface, deliberately. What is settled is that whatever answers that is not something which must exist before the mesh does, so it can be decided late or replaced — which being substrate would have prevented.
This commit is contained in:
@@ -95,6 +95,7 @@ python3 00-META/checks/index.py fail if stale
|
||||
- **0028** — [The substrate supplies the control plane and nothing else](0028-the-substrate-supplies-the-control-plane-and-nothing-else.md)
|
||||
- **0029** — [A network is a shape, because an action cannot be undone](0029-a-network-is-a-shape-because-an-action-cannot-be-undone.md)
|
||||
- **0030** — [Data outlives the mesh that declared it](0030-data-outlives-the-mesh-that-declared-it.md)
|
||||
- **0031** — [The control plane authenticates nobody, so identity is a module](0031-the-control-plane-authenticates-nobody.md)
|
||||
|
||||
### What runs on them, and how it gets there
|
||||
|
||||
|
||||
Reference in New Issue
Block a user