Reconcile: adopt initialization's consolidated HQ as canonical, re-home this session's new work #24
@@ -5,7 +5,7 @@ code:
|
|||||||
- mesh-control internal/inventory/secrets.go
|
- mesh-control internal/inventory/secrets.go
|
||||||
- mesh-control cmd/mesh-control/rotate.go
|
- mesh-control cmd/mesh-control/rotate.go
|
||||||
- mesh-control examples/postgres-provisioner
|
- mesh-control examples/postgres-provisioner
|
||||||
updated: 2026-08-31
|
updated: 2026-09-01
|
||||||
decisions:
|
decisions:
|
||||||
- 02-DECISIONS/0001-mesh-brokers-nodes-host-agents-think.md
|
- 02-DECISIONS/0001-mesh-brokers-nodes-host-agents-think.md
|
||||||
- 02-DECISIONS/0009-modules-and-the-graph.md
|
- 02-DECISIONS/0009-modules-and-the-graph.md
|
||||||
@@ -35,9 +35,21 @@ Three separate faults, and it is worth naming them apart because they have diffe
|
|||||||
## What replaces it
|
## What replaces it
|
||||||
|
|
||||||
**Every pair has its own credential.** A provision between one consumer and one provider is one
|
**Every pair has its own credential.** A provision between one consumer and one provider is one
|
||||||
password, made once and kept. So rotating a machine's credential touches one role and leaves every
|
password, made once and kept. So rotating a credential touches one role and leaves every other
|
||||||
other consumer alone — and *who holds this* is a query rather than an assumption. That alone
|
consumer alone — and *who holds this* is a query rather than an assumption. That alone removes the
|
||||||
removes the first fault: there is no shared secret to fan out.
|
first fault: there is no shared secret to fan out.
|
||||||
|
|
||||||
|
**A consumer is a module on a machine, not a machine.** This was written as though a pair were two
|
||||||
|
machines, and built that way, and it was wrong in a way that only shows on a real node
|
||||||
|
([`022`](../../04-ISSUES/022-one-credential-per-node-per-provision-not-per-module/00-report.md)):
|
||||||
|
a machine running several services against one database server had one credential between them.
|
||||||
|
The provider refused to plan at all, and the consuming node did not refuse — it gave the first
|
||||||
|
module a credential and the rest nothing.
|
||||||
|
|
||||||
|
Two modules on one node are as separate as two on different nodes. They are different containers,
|
||||||
|
with different data, and one login opening both is the thing this page exists to prevent. It is
|
||||||
|
also what makes withdrawal possible: one role per machine cannot express *this module no longer
|
||||||
|
has a login and the others still do*.
|
||||||
|
|
||||||
**The change and the delivery are one command.** `rotate` discards the credential and sends both
|
**The change and the delivery are one command.** `rotate` discards the credential and sends both
|
||||||
ends, and it does the sending itself. Leaving that to whoever remembers is the second fault
|
ends, and it does the sending itself. Leaving that to whoever remembers is the second fault
|
||||||
|
|||||||
Reference in New Issue
Block a user