diff --git a/04-ISSUES/021-a-consumer-on-the-providers-machine-is-given-no-credential/00-report.md b/04-ISSUES/021-a-consumer-on-the-providers-machine-is-given-no-credential/00-report.md index 8df93be..a08c6fa 100644 --- a/04-ISSUES/021-a-consumer-on-the-providers-machine-is-given-no-credential/00-report.md +++ b/04-ISSUES/021-a-consumer-on-the-providers-machine-is-given-no-credential/00-report.md @@ -1,8 +1,8 @@ --- -status: located +status: fixed opened: 2026-09-01 located-in: [mesh-control] -fixed-by: +fixed-by: mesh-control df62bb5 amended-design: --- @@ -69,3 +69,22 @@ them as consumers. readable secret for local consumers would be a hole opened for convenience. - **Refusing must stay refusing.** A requirement nothing answers is still refused; this is about a requirement that *was* answered. + +## Fixed + +A requirement answered on this machine is still a requirement. Resolution now records a need for +it, so a credential is made, the provider is told who asked, and the consumer's file is written — +the same as if the two were on different machines. + +The reasoning that made it a gap is now written where it was assumed: the machine is not a trust +boundary once both ends are containers, and treating it as one gave the commonest arrangement of +all — a service and its database on one node — the weakest handling. + +Two later issues came out of the same mistaken instinct and are worth reading together: +[`022`](../022-one-credential-per-node-per-provision-not-per-module/00-report.md), where the +machine was treated as an *identity* rather than a boundary, and +[`023`](../023-a-consumer-cannot-build-a-connection-string/00-report.md), where the consumer was +given a password and never told the name to present with it. + +*Closed 2026-09-01. The fix landed the same day and this record was left open by oversight — the +code and the tests were in place for hours while the record still said `located`.*