ADR 0086: a secret reaches a process as a file, and an exception is declared

Closes issue 041 by decision and by code on the same branch: the catalogue
engine refuses a secret in a container's env, and a secret-carrying env-file
unless the container declares its reason; the controller reads all six of
its credentials from files; design 13 states the rule and how it is checked.
This commit is contained in:
2026-09-21 10:10:33 +02:00
parent 7015bf58ac
commit ec7b6e0748
3 changed files with 102 additions and 5 deletions
@@ -1,9 +1,9 @@
---
status: open
status: resolved
opened: 2026-09-10
located-in: []
fixed-by:
amended-design:
located-in: [mesh-controller internal/catalogue, mesh-catalog modules/mesh-controller]
fixed-by: ADR 0086; mesh-controller feat/secret-not-in-environment (envfile twins for the broker settings, catalogue refusal of secrets in env / undeclared env-file); mesh-catalog (the controller reads its six credentials from files; 35 containers declare their exception); mesh-host (the installer delivers any MESH_…_FILE own secret)
amended-design: 03-DESIGN/01-to-be/13-credentials-and-their-rotation.md
---
# 041 — A credential the mesh took care to seal ends up in the process environment
@@ -65,3 +65,11 @@ environment; 28 catalogue manifests use env-file for a secret, and nothing in th
engine refuses a `${secret:…}` placeholder in one. The vault work of
[ADR 0085](../../02-DECISIONS/0085-a-secret-is-a-provision.md) rests on the seal this weakens.
## Resolved 2026-09-21
By [ADR 0086](../../02-DECISIONS/0086-a-secret-reaches-a-process-as-a-file.md): a secret reaches
a process as a file, an environment exception is declared with a reason, and the catalogue engine
refuses the undeclared shape. The controller, the instance this was opened on, reads all six of
its credentials from files. The 35 other containers carry a declared reason; converting each where
its software accepts a path remains per-module work and is not this issue's.