From db5ff5a5ee04cee21a8acd745840be1c70976786 Mon Sep 17 00:00:00 2001 From: jochens Date: Fri, 2 Oct 2026 02:44:24 +0200 Subject: [PATCH] Issue 195: every assigned module is counted as a bus user without a credential The status warning names 49 users; 48 are modules that never speak on the bus, and the one real fault, a declared broker secret filled with a generated value, looked the same as the rest. --- .../00-report.md | 62 +++++++++++++++++++ 1 file changed, 62 insertions(+) create mode 100644 04-ISSUES/195-every-assigned-module-is-counted-as-a-bus-user-without-a-credential/00-report.md diff --git a/04-ISSUES/195-every-assigned-module-is-counted-as-a-bus-user-without-a-credential/00-report.md b/04-ISSUES/195-every-assigned-module-is-counted-as-a-bus-user-without-a-credential/00-report.md new file mode 100644 index 0000000..f21075e --- /dev/null +++ b/04-ISSUES/195-every-assigned-module-is-counted-as-a-bus-user-without-a-credential/00-report.md @@ -0,0 +1,62 @@ +--- +status: open +opened: 2026-10-02 +located-in: [] +fixed-by: +amended-design: +--- + +# 195 — Every assigned module is counted as a bus user without a credential, and the real gaps are lost in the count + +## What was observed + +`status`, and `plan` for any machine, open with one line before anything else: + +``` +the bus's user list leaves out 49 user(s) the mesh has minted no credential for: ., … +Each is a user that cannot connect until one is issued +``` + +The 49 are spread over four machines and name 26 distinct modules. Checked against the catalogue on +2026-10-02: + +| what the module's definition says | modules | +|---|---| +| declares an own secret named `broker` | 1 — the route proxy, which needed a bus account for issue 191 | +| declares no `broker` secret, and emits, consumes and serves nothing on the bus | 17 — the packet filter, the intrusion filter, the ssh daemon, the resolver configuration, the certificate authority, the broker itself and others | +| declares no `broker` secret, and **emits events** | 1 | +| not in this catalogue, so not checked | 7 | + +So the line counts every module assigned anywhere as a bus user. For almost all of them that is not a +missing credential. A module with no `broker` secret has nowhere to receive one, and the mesh already +says an account nothing reads is an orphan ([issue 078](../078-a-delivered-secret-is-accepted-under-any-name/00-report.md)). + +Two real gaps sit inside the count and cannot be told from the noise: + +- **A declared `broker` secret was filled with a value that is not an account.** Before its account was + issued, the route proxy's plan on both machines already carried a sealed `broker` file, while the same + status line said no credential had been minted for it. A push had made the declared secret the way it + makes any own secret. The module would have started with a credential the bus does not know, and + nothing would have said why. It was found only because the account was being issued by hand. +- **A module that emits events declares no way to reach the bus.** Its events can go nowhere, and no + check refuses that. + +## Why it matters + +**A warning that is always on is read as never on.** The line names 49 users on every `status` and every +`plan`. An operator, or an agent, learns to scroll past it. The one entry that was a real fault looked +exactly like the 48 that were not. + +**The fault that was real is the silent kind.** A module whose broker credential is a generated value +starts, fails to authenticate, and reports that three layers away from the cause. That is the failure +the composition already refuses for a secret that was never made at all ("declared and not made"). Here +a value was made, so the refusal never fired. + +## Open questions + +- Should a bus user be composed for a module that declares no `broker` secret at all? If not, the line + shrinks to the modules that can actually use an account. +- Is a `broker` secret ever correctly made by the generic generator? If not, should composition refuse + a declared `broker` until it is issued, or should the mesh issue it as part of placing the module? +- Should a module that emits, consumes or serves on the bus be refused when it declares no `broker` + secret? -- 2.54.0