--- status: open opened: 2026-10-02 located-in: [] fixed-by: amended-design: --- # 195 — Every assigned module is counted as a bus user without a credential, and the real gaps are lost in the count ## What was observed `status`, and `plan` for any machine, open with one line before anything else: ``` the bus's user list leaves out 49 user(s) the mesh has minted no credential for: ., … Each is a user that cannot connect until one is issued ``` The 49 are spread over four machines and name 26 distinct modules. Checked against the catalogue on 2026-10-02: | what the module's definition says | modules | |---|---| | declares an own secret named `broker` | 1 — the route proxy, which needed a bus account for issue 191 | | declares no `broker` secret, and emits, consumes and serves nothing on the bus | 17 — the packet filter, the intrusion filter, the ssh daemon, the resolver configuration, the certificate authority, the broker itself and others | | declares no `broker` secret, and **emits events** | 1 | | not in this catalogue, so not checked | 7 | So the line counts every module assigned anywhere as a bus user. For almost all of them that is not a missing credential. A module with no `broker` secret has nowhere to receive one, and the mesh already says an account nothing reads is an orphan ([issue 078](../078-a-delivered-secret-is-accepted-under-any-name/00-report.md)). Two real gaps sit inside the count and cannot be told from the noise: - **A declared `broker` secret was filled with a value that is not an account.** Before its account was issued, the route proxy's plan on both machines already carried a sealed `broker` file, while the same status line said no credential had been minted for it. A push had made the declared secret the way it makes any own secret. The module would have started with a credential the bus does not know, and nothing would have said why. It was found only because the account was being issued by hand. - **A module that emits events declares no way to reach the bus.** Its events can go nowhere, and no check refuses that. ## Why it matters **A warning that is always on is read as never on.** The line names 49 users on every `status` and every `plan`. An operator, or an agent, learns to scroll past it. The one entry that was a real fault looked exactly like the 48 that were not. **The fault that was real is the silent kind.** A module whose broker credential is a generated value starts, fails to authenticate, and reports that three layers away from the cause. That is the failure the composition already refuses for a secret that was never made at all ("declared and not made"). Here a value was made, so the refusal never fired. ## Open questions - Should a bus user be composed for a module that declares no `broker` secret at all? If not, the line shrinks to the modules that can actually use an account. - Is a `broker` secret ever correctly made by the generic generator? If not, should composition refuse a declared `broker` until it is issued, or should the mesh issue it as part of placing the module? - Should a module that emits, consumes or serves on the bus be refused when it declares no `broker` secret?