Asked by the operator on 2026-10-01: every password in the vault, rotatable; sonarr's manifest should get nzbget's and qbittorrent's credential and address through provisioning.
Where it stands. The address half works today: sonarr requires nzbget-api, qbittorrent-api, jackett-api; each provider serves scheme/port/username (settled with its assignment), the bind file carries them, and sonarr's step writes them in. The credential half does not fit ADR 0048: nzbget, qbittorrent, jackett, sonarr/radarr/lidarr and plex each hold one credential (a control password, a WebUI password, one API key, a token), so no provisioner can create a login per consumer. ADR 0113 therefore leaves them accepted — on ace today 47 own secrets and 12 pair credentials are accepted (nzbget-api, jackett-api, sonarr/radarr/lidarr-api, plex-api, nzbget's and influxdb's admin, mssql sa, supabase's nine…), 9 own and the rest of the pairs made. Accepted values are in the vault (sealed to both ends and the operator, recoverable), but rotating one is a person accepting a new value and changing the application by hand; a qbittorrent-api pair nobody could accept sits made and wrong.
Proposal — a shared credential provision. An offer may say {"name": "qbittorrent-api", "credential": {"own": "password"}}: the provider's own secret passwordis the credential every consumer receives. Because the vault stores no plaintext, a value can't be re-sealed to a later consumer; so the vault keeps one record per (provider assignment, provision) sealed to the provider's node, every current consumer's node and the operator, and re-mints it for all of them at once whenever a consumer binds or unbinds or a rotation is asked — the provider marks it applied (its init/provisioner sets the software's one credential from the file: qbittorrent's WebUI password via its API or PBKDF2 at start, nzbget's NZBGET_USER/PASS, jackett's APIKey in ServerConfig.json, the arrs' <ApiKey> in config.xml), consumers read at start (recreated on change, as today). The sdk harness calls create(p) with the same password for every consumer — idempotent for a shared credential; holds checks the software still takes it. Rotation (#231) then rotates these in place, staged per ADR 0114's single-party case. plex is the exception: its token is issued by plex.tv and can't be set, so plex-api stays accepted unless the plex module reads the token from Preferences.xml and delivers it to the vault (0113: "a secret a backend issued is rotated by the module that holds the backend… delivering the new value to the vault" — a module→vault delivery that doesn't exist yet).
Cost of adoption on ace: nothing to accept any more for the six media providers; luffy's unknown qBittorrent password is replaced by the vault's (recoverable with the operator key); the provider inits are catalogue work in mesh-media-catalog.
Asked by the operator on 2026-10-01: every password in the vault, rotatable; sonarr's manifest should get nzbget's and qbittorrent's credential and address through provisioning.
**Where it stands.** The address half works today: `sonarr` requires `nzbget-api`, `qbittorrent-api`, `jackett-api`; each provider `serves` scheme/port/username (settled with its assignment), the bind file carries them, and sonarr's step writes them in. The credential half does not fit ADR 0048: nzbget, qbittorrent, jackett, sonarr/radarr/lidarr and plex each hold **one** credential (a control password, a WebUI password, one API key, a token), so no provisioner can create a login per consumer. ADR 0113 therefore leaves them `accepted` — on ace today 47 own secrets and 12 pair credentials are `accepted` (nzbget-api, jackett-api, sonarr/radarr/lidarr-api, plex-api, nzbget's and influxdb's admin, mssql sa, supabase's nine…), 9 own and the rest of the pairs `made`. Accepted values are in the vault (sealed to both ends and the operator, recoverable), but rotating one is a person accepting a new value and changing the application by hand; a `qbittorrent-api` pair nobody could accept sits `made` and wrong.
**Proposal — a shared credential provision.** An offer may say `{"name": "qbittorrent-api", "credential": {"own": "password"}}`: the provider's own secret `password` *is* the credential every consumer receives. Because the vault stores no plaintext, a value can't be re-sealed to a later consumer; so the vault keeps **one** record per (provider assignment, provision) sealed to the provider's node, every current consumer's node and the operator, and **re-mints it for all of them at once** whenever a consumer binds or unbinds or a rotation is asked — the provider marks it *applied* (its init/provisioner sets the software's one credential from the file: qbittorrent's WebUI password via its API or PBKDF2 at start, nzbget's `NZBGET_USER/PASS`, jackett's `APIKey` in ServerConfig.json, the arrs' `<ApiKey>` in config.xml), consumers *read at start* (recreated on change, as today). The sdk harness calls `create(p)` with the same password for every consumer — idempotent for a shared credential; `holds` checks the software still takes it. Rotation (#231) then rotates these in place, staged per ADR 0114's single-party case. plex is the exception: its token is issued by plex.tv and can't be set, so `plex-api` stays accepted unless the plex module reads the token from Preferences.xml and *delivers* it to the vault (0113: "a secret a backend issued is rotated by the module that holds the backend… delivering the new value to the vault" — a module→vault delivery that doesn't exist yet).
**Cost of adoption on ace:** nothing to accept any more for the six media providers; luffy's unknown qBittorrent password is replaced by the vault's (recoverable with the operator key); the provider inits are catalogue work in mesh-media-catalog.
Related: ADR 0048, 0092, 0113, 0114; #231 (rotation verb); #228.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Asked by the operator on 2026-10-01: every password in the vault, rotatable; sonarr's manifest should get nzbget's and qbittorrent's credential and address through provisioning.
Where it stands. The address half works today:
sonarrrequiresnzbget-api,qbittorrent-api,jackett-api; each providerservesscheme/port/username (settled with its assignment), the bind file carries them, and sonarr's step writes them in. The credential half does not fit ADR 0048: nzbget, qbittorrent, jackett, sonarr/radarr/lidarr and plex each hold one credential (a control password, a WebUI password, one API key, a token), so no provisioner can create a login per consumer. ADR 0113 therefore leaves themaccepted— on ace today 47 own secrets and 12 pair credentials areaccepted(nzbget-api, jackett-api, sonarr/radarr/lidarr-api, plex-api, nzbget's and influxdb's admin, mssql sa, supabase's nine…), 9 own and the rest of the pairsmade. Accepted values are in the vault (sealed to both ends and the operator, recoverable), but rotating one is a person accepting a new value and changing the application by hand; aqbittorrent-apipair nobody could accept sitsmadeand wrong.Proposal — a shared credential provision. An offer may say
{"name": "qbittorrent-api", "credential": {"own": "password"}}: the provider's own secretpasswordis the credential every consumer receives. Because the vault stores no plaintext, a value can't be re-sealed to a later consumer; so the vault keeps one record per (provider assignment, provision) sealed to the provider's node, every current consumer's node and the operator, and re-mints it for all of them at once whenever a consumer binds or unbinds or a rotation is asked — the provider marks it applied (its init/provisioner sets the software's one credential from the file: qbittorrent's WebUI password via its API or PBKDF2 at start, nzbget'sNZBGET_USER/PASS, jackett'sAPIKeyin ServerConfig.json, the arrs'<ApiKey>in config.xml), consumers read at start (recreated on change, as today). The sdk harness callscreate(p)with the same password for every consumer — idempotent for a shared credential;holdschecks the software still takes it. Rotation (#231) then rotates these in place, staged per ADR 0114's single-party case. plex is the exception: its token is issued by plex.tv and can't be set, soplex-apistays accepted unless the plex module reads the token from Preferences.xml and delivers it to the vault (0113: "a secret a backend issued is rotated by the module that holds the backend… delivering the new value to the vault" — a module→vault delivery that doesn't exist yet).Cost of adoption on ace: nothing to accept any more for the six media providers; luffy's unknown qBittorrent password is replaced by the vault's (recoverable with the operator key); the provider inits are catalogue work in mesh-media-catalog.
Related: ADR 0048, 0092, 0113, 0114; #231 (rotation verb); #228.