Files
hq/02-DECISIONS/0032-the-local-account-owns-the-mesh.md
jschoubben fccac61e58 The board is a web application, not a category
Supersedes 0032, which decided the right thing and described it wrongly.
The decision is unchanged: the account that installed the host owns the
mesh, and there is no user model.

What was wrong was inventing "a surface that delegates authentication"
for the board. It is a web application with a login, in the way every
web application has a login. That is a fact about an application, not a
property of the mesh.

The cost was not cosmetic. It made the identity module look like part of
the mesh's authority — something the mesh depends on to know who anybody
is — when the mesh knows nothing about people at all and one of the
applications running on it happens to have a login.

Keeps the line that is worth writing down, and states it more plainly:
signing in to an application must not become authority over the mesh.
Today it cannot, because the board reads and does not act. The moment it
can assign a module, whoever it lets in has mesh authority — and it
would arrive as a feature rather than as a decision. So a surface that
can change the mesh is a change to who owns the mesh, and is taken as
one. Not forbidden; just not something that turns up in a pull request
titled "add assign button".
2026-08-31 21:08:39 +02:00

3.9 KiB

topic, status, date, deciders, reconstructed, extends, superseded-by
topic status date deciders reconstructed extends superseded-by
how we work superseded 2026-08-31 jochen false 02-DECISIONS/0031-the-control-plane-authenticates-nobody.md 02-DECISIONS/0034-the-local-account-owns-the-mesh.md

32. The local account owns the mesh; a surface delegates to a module

Context

ADR 0031 settled that the control plane authenticates nobody, and deliberately left one thing open: how a person signing in to a mesh surface is authenticated. This answers it, and answers a question 0031 did not ask — who owns the mesh at all.

There was no answer, and the absence was invisible because every operation so far has been run by the person sitting at the machine. Nothing had to say whether that was the design or the circumstance.

Decision

The account that installed the host owns the mesh on that node. Authority is a local login, and there is nothing else to hold.

No mesh user model. No accounts, no roles, no grants, nothing to administer. A person with a shell on a node can do anything the mesh can do there, because that is already true and pretending otherwise would be a boundary that does not exist.

This follows from what was already decided rather than adding to it. ADR 0004 says there is no authorisation between nodes — every node is the operator's own, so a message from one is a message from them, and the mesh boundary is therefore the security boundary. A user model inside that boundary would guard nothing: anyone who could be stopped by it could equally read the node's key off the disk.

The board is different, and the difference is the network. A surface reachable by a browser has to know who is asking, because the people reaching it are not, by construction, people with a shell on the machine. So the board delegates to an OAuth provider — which is a module.

What this does not change

The identity provider is still not substrate (ADR 0031). A surface delegating authentication is not the control plane delegating it. The control plane runs, applies declarations and reaches nodes with no identity provider in existence; only the board needs one, and only to decide whose browser it is talking to.

The test is unchanged and still answers no: does the control plane need it in order to run?

Consequences

The board depends on a module, and says so. An ordinary edge in the graph, which means the board cannot come up before the provider it authenticates against — stated as a dependency rather than discovered as an outage.

Moving the identity provider takes the board with it. During that module's own conversion the board is unavailable, and that is acceptable: it is a surface, nothing depends on it, and a brief interruption is the trade already accepted everywhere else. Nothing that keeps a service serving goes through it.

Anyone with a shell on a node has full authority there. Written down rather than left implied, because it is the sentence that decides who gets an account on a machine. The protection is the machine's own login, and the overlay that keeps the machine unreachable from outside (ADR 0007).

A node cannot be operated by somebody without a login on it. Deliberate, and the cost of having no user model: there is no way to give a person authority over one node without giving them a shell there. If that is ever wanted, it is a new decision and not a gap in this one.

References

  • ADR 0031 — the control plane authenticates nobody; this answers what it left open
  • ADR 0004 — no authorisation between nodes, and why the mesh boundary is the security boundary
  • 03-DESIGN/01-to-be/11-a-board.md — the surface this is about