2.6 KiB
status, opened, located-in, fixed-by, amended-design
| status | opened | located-in | fixed-by | amended-design | ||
|---|---|---|---|---|---|---|
| resolved | 2026-09-21 |
|
ADR 0098; mesh-catalog multiple-fixes (the authority makes its own root and serves it; the proxy fetches it through a gate); proven by the route-forwarding bed | 03-DESIGN/01-to-be/08-connectivity.md |
A served fact made at first start cannot be served, so the catalogue's authority cannot start
Symptom, as observed
The catalogue's certificate authority module declares its root certificate, its root key and
that key's password as its own secrets, and writes each into a file the container is told to
initialise from. An own secret nobody delivers is minted by the mesh as random bytes, and random
bytes are not a certificate: issued that way, the authority cannot initialise. It could be
raised by an operator making a root with openssl and delivering all three through secret accept — the whole-mesh bed did exactly that, and has not run since it was converted — but a
module that only starts once a person has hand-made its key material is not a module a mesh
can raise. Found while converting the route-forwarding bed to the catalogue's proxy, which
requires the authority beside it.
The authority can make its own root at first start — the certificate bed raises it that way and
it issues within a second. What it cannot do then is tell the mesh what that root is: a
consumer of acme-ca is given ${bound:acme-ca:root} from the provider's serves, which is
written in the manifest before anything runs.
Why it matters beyond this instance
- Two kinds of secret the vocabulary does not distinguish. A value the mesh may invent (a password) and a value only the module can produce (a key pair, a certificate) are both "own secrets", and the mesh invents both.
- A served fact that exists only after first start has no way into a binding. Anything a module generates and its consumers must trust — a root, a public key, a fingerprint — is in the same position.
- Every consumer of
acme-ca, which today is the route proxy, is blocked with it.
What would close it
Either a module may say a secret is made by the module — the mesh reserves the name, the module writes the value once, the mesh takes custody of it and delivers it where it is bound — or a served fact may be contributed at run time by the provider's runtime rather than written in its manifest. The first is the smaller change and covers the root certificate; the second is what a fingerprint or a public key wants. Decided, then the authority raised in the lab beside the proxy, which is the route-forwarding bed's conversion.