diff --git a/03-DESIGN/01-to-be/00-work-breakdown.md b/03-DESIGN/01-to-be/00-work-breakdown.md index bbcd67a..6d7fdc4 100644 --- a/03-DESIGN/01-to-be/00-work-breakdown.md +++ b/03-DESIGN/01-to-be/00-work-breakdown.md @@ -161,6 +161,19 @@ service between systems. **So there is a step before any of this: read the current environment out of the old system**, because adoption means supplying those values and they live in its files today. +**And there is a failure worse than losing data, which is likelier.** A database image consumes its +password environment variable **only when its data directory is empty**. Everything here keeps its +data on a persistent directory, so the role holds whatever password it was created with, for ever. +Regenerate that variable and the application moves on while the database does not — permanently, +because nothing reconciles it. Eight modules are in that state today, working only because nobody +has regenerated their credential since their data directory was created. + +*Where the detail lives:* this is operational and names machines, so it is in the mesh's own +knowledge base rather than here — `migration/where-service-data-lives`, which surveys where every +service's data actually sits and what each stop or removal would cost, and +`troubleshooting/db-password-frozen-at-first-init` for the lockout itself. **This document says the +rule; those say the specifics.** + *Corrected 2026-08-31 — an earlier version of this paragraph made that sound more dangerous than it is.* A sealed secret is not unreadable; it is sealed **to the node**, which holds the private half and writes the plaintext into the module's own file. The value is there, on the machine, as an