--- status: located opened: 2026-09-21 located-in: [mesh-catalog modules/step-ca, mesh-controller internal/catalogue (serves)] fixed-by: amended-design: --- # A served fact made at first start cannot be served, so the catalogue's authority cannot start ## Symptom, as observed The catalogue's certificate authority module declares its root certificate, its root key and that key's password as its own secrets, and writes each into a file the container is told to initialise from. The mesh mints an own secret as random bytes. Random bytes are not a certificate: as written, the authority cannot initialise, and no bed has ever raised it — the whole-mesh bed that names it has not run since it was converted. Found while converting the route-forwarding bed to the catalogue's proxy, which requires the authority beside it. The authority can make its own root at first start — the certificate bed raises it that way and it issues within a second. What it cannot do then is tell the mesh what that root is: a consumer of `acme-ca` is given `${bound:acme-ca:root}` from the provider's `serves`, which is written in the manifest before anything runs. ## Why it matters beyond this instance - **Two kinds of secret the vocabulary does not distinguish.** A value the mesh may invent (a password) and a value only the module can produce (a key pair, a certificate) are both "own secrets", and the mesh invents both. - **A served fact that exists only after first start** has no way into a binding. Anything a module generates and its consumers must trust — a root, a public key, a fingerprint — is in the same position. - Every consumer of `acme-ca`, which today is the route proxy, is blocked with it. ## What would close it Either a module may say a secret is *made by the module* — the mesh reserves the name, the module writes the value once, the mesh takes custody of it and delivers it where it is bound — or a served fact may be *contributed at run time* by the provider's runtime rather than written in its manifest. The first is the smaller change and covers the root certificate; the second is what a fingerprint or a public key wants. Decided, then the authority raised in the lab beside the proxy, which is the route-forwarding bed's conversion.