Files
hq/04-ISSUES/076-a-served-fact-made-at-first-start-cannot-be-served/01-diagnosis.md

2.1 KiB

Diagnosis — 2026-09-21

  1. The certificate bed already raised the same authority image with no root supplied, and it made its own root and issued within a second. The manifest's three minted "secrets" were not needed by the authority; they were needed by the consumer, which was handed the root as a served fact.
  2. Of the three ways to get a fact made at first start to a consumer, two need a channel from a node up to the mesh that does not exist. The third needs nothing new: the provider serves the fact at a path, and the consumer fetches it over the mesh network in a gate before it starts.

Located in: the two manifests. Decided in ADR 0098.

Proven the same day: the route-forwarding bed raises the authority, the proxy and a consumer from the catalogue on one node and serves a public name through the proxy. Two things the run taught, both about the bed rather than the decision:

  • The authority certifies itself for the machine's private-network address, which is what a consumer on any node dials. A machine raised from the foundation bundle has no such address until it is placed on the overlay, so a bed must place it first — as a hub of one, the way a real first node is.
  • With the overlay's networking and the three modules in one push, the proxy's fetch of the roots timed out at the private-network address; with the overlay converged first and the modules pushed after, it passes. The order between modules is not the cause: the controller applies a node's providers before its consumers. The overlay interface and the filter that admits it were not there yet, and the gate, as first written, tried once with no timeout — a fetch that hangs holds the node's whole apply. The gate now retries with a timeout and refuses a body that is not a certificate. A consumer whose first start dials a provider still assumes the provider's network exists; a fact fetched once per declaration is issue 077.