The board is published publicly, which decides everything else about it

Assumed throughout and stated nowhere — the wrong way round for the most
consequential fact about this component.

A board reachable only over the private network would sit inside the
boundary 0004 already calls the security boundary, and a login there
would guard a room whose door is inside the building. This one faces the
internet, so its login is a perimeter rather than defence in depth.

Which makes the identity provider the mesh's outermost gate. The board
presents the control plane, and the control plane's networked surfaces
can change the mesh (0035) — so whoever that provider admits can assign
modules, from anywhere. Written flatly because it is easy to arrive at
one reasonable step at a time and then be surprised by.

What follows is not the board's own design: who may log in is a decision
about the mesh rather than about an application; a public name needs a
certificate from an authority the world trusts, which is why that work
exists; and the provider going wrong in the permissive direction is a
mesh-wide exposure with no local symptom.

The command line is unaffected and is why this is tolerable — it
authenticates through nothing and answers to the machine's own login, so
the mesh stays operable by somebody standing at it whatever happens to
the gate. That is the property to protect if the rest is ever traded
away.
This commit is contained in:
2026-08-31 21:26:06 +02:00
parent a1a10e9ed2
commit f801b4b3e2
+33
View File
@@ -49,6 +49,39 @@ client. A board that queries `inventory` is a second control plane with a worse
like last time". If a question is slow to answer, the answer belongs in the context that owns it,
where everything else asking gets it too.
## Where it is reachable from, which decides everything else about it
*Written 2026-08-31. It was assumed throughout and stated nowhere, which is the wrong way round
for the most consequential fact about this component.*
**The board is published on a public name.** Not reachable only over the private network — on the
internet, behind the reverse proxy, like any other published workload.
**So its login is a perimeter, not defence in depth.** A board on the overlay alone would sit
inside the boundary that [ADR 0004](../../02-DECISIONS/0004-a-node-and-how-it-joins.md) already
calls the security boundary, and a login there would guard a room whose door is inside the
building. This one faces everybody.
**Which makes the identity provider the mesh's outermost gate.** The board is a presentation layer
over the control plane and the control plane's networked surfaces can change the mesh
([ADR 0035](../../02-DECISIONS/0035-one-implementation-several-surfaces.md)), so **whoever that
provider admits can assign modules, from anywhere.** Said flatly because it is easy to arrive at
one reasonable step at a time and then be surprised by.
Three things follow, and none of them are the board's own design:
- **Who may log in, and how, is a decision about the mesh** rather than about an application. A
realm that lets somebody in has let them into the mesh.
- **A public name needs a public certificate**, from an authority the world trusts rather than the
mesh's own — which is why that exists at all.
- **The provider failing is not only "the board is down".** Its configuration going wrong in the
other direction — a realm that admits too much — is a mesh-wide exposure with no local symptom.
**The command line is unaffected and is the reason this is tolerable.** It authenticates through
nothing, needs no network, and answers to the machine's own login — so the mesh remains operable
by somebody standing at it whatever happens to the gate. *That is the property to protect if the
rest of this is ever traded away.*
## What it is not
- **Not the way to change things.** Reading is the whole of it to begin with. Every action the