42 lines
2.5 KiB
Markdown
42 lines
2.5 KiB
Markdown
---
|
|
status: resolved
|
|
opened: 2026-09-20
|
|
located-in: [mesh-host internal/bootstrap, mesh-host examples/foundation-first-node.lock]
|
|
fixed-by: mesh-host PR 14 (e30a6b0), mesh-controller PR 34 (6b695c8), mesh-catalog PR 30 (d03520f), mesh-lab PR 39 (7e2e97f); proven by the one-node genesis bed step V5, 22/22
|
|
amended-design: 03-DESIGN/01-to-be/24-the-secrets-vault.md
|
|
---
|
|
|
|
# The foundation is raised with fixed credentials, and they stay
|
|
|
|
## Symptom, as observed
|
|
|
|
The foundation bundle raises the store with a superuser password that is the literal word
|
|
`bootstrap`, and the broker with its image's default administrator, `guest` / `guest`. The
|
|
installer then carries both into the mesh through `secret accept`, sealed to the control-node's
|
|
key, marked `accepted` so the mesh will never replace them — which is correct for a credential
|
|
that already created the databases, and means the well-known value is now permanent.
|
|
|
|
Every module's own secret minted afterwards is random and sealed. The two that everything else
|
|
rests on are not random, and there is no operator key at genesis for anything to be sealed to.
|
|
|
|
## Why it matters beyond this instance
|
|
|
|
- **These are the root secrets.** A mesh whose store superuser is a published constant is a mesh
|
|
whose every provisioned credential is one connection away, from any node that can reach 5432.
|
|
- **It is invisible.** `secret accept` reports the value as sealed to the machine and unreadable by
|
|
the mesh, which is true, and says nothing about where it came from.
|
|
- **Rotation cannot fix it later.** An accepted own secret is never remade by the mesh, and there is
|
|
no `rotate` for own secrets; the only path is to change it on the server by hand and accept it
|
|
again, which is the manual rotation the as-is design records as having taken services down.
|
|
|
|
## What closes it
|
|
|
|
[ADR 0085](../../02-DECISIONS/0085-a-secret-is-a-provision.md), amended, and design
|
|
[24](../../03-DESIGN/01-to-be/24-the-secrets-vault.md): genesis makes the operator key first,
|
|
mints real credentials for the store and broker before the bundle raises them (or changes them
|
|
on the running servers before handing over), accepts those, and installs `mesh-vault` so the
|
|
operator-sealed export exists from the first push. Built on `feat/secrets-vault` across mesh-host, mesh-controller and mesh-catalog, and proven by
|
|
the one-node genesis bed: the template's password is refused by the store, the export and the
|
|
vault's copy hold no plaintext, and the superuser recovered off the mesh with the operator key
|
|
opens the store.
|