Supersedes 0032, which decided the right thing and described it wrongly. The decision is unchanged: the account that installed the host owns the mesh, and there is no user model. What was wrong was inventing "a surface that delegates authentication" for the board. It is a web application with a login, in the way every web application has a login. That is a fact about an application, not a property of the mesh. The cost was not cosmetic. It made the identity module look like part of the mesh's authority — something the mesh depends on to know who anybody is — when the mesh knows nothing about people at all and one of the applications running on it happens to have a login. Keeps the line that is worth writing down, and states it more plainly: signing in to an application must not become authority over the mesh. Today it cannot, because the board reads and does not act. The moment it can assign a module, whoever it lets in has mesh authority — and it would arrive as a feature rather than as a decision. So a surface that can change the mesh is a change to who owns the mesh, and is taken as one. Not forbidden; just not something that turns up in a pull request titled "add assign button".
80 lines
3.9 KiB
Markdown
80 lines
3.9 KiB
Markdown
---
|
|
topic: how we work
|
|
status: superseded
|
|
date: 2026-08-31
|
|
deciders: jochen
|
|
reconstructed: false
|
|
extends: 02-DECISIONS/0031-the-control-plane-authenticates-nobody.md
|
|
superseded-by: 02-DECISIONS/0034-the-local-account-owns-the-mesh.md
|
|
---
|
|
|
|
# 32. The local account owns the mesh; a surface delegates to a module
|
|
|
|
## Context
|
|
|
|
[ADR 0031](0031-the-control-plane-authenticates-nobody.md) settled that the control plane
|
|
authenticates nobody, and deliberately left one thing open: **how a person signing in to a mesh
|
|
surface is authenticated.** This answers it, and answers a question 0031 did not ask — *who owns
|
|
the mesh at all.*
|
|
|
|
**There was no answer, and the absence was invisible** because every operation so far has been run
|
|
by the person sitting at the machine. Nothing had to say whether that was the design or the
|
|
circumstance.
|
|
|
|
## Decision
|
|
|
|
**The account that installed the host owns the mesh on that node.** Authority is a local login,
|
|
and there is nothing else to hold.
|
|
|
|
**No mesh user model.** No accounts, no roles, no grants, nothing to administer. A person with a
|
|
shell on a node can do anything the mesh can do there, because that is already true and pretending
|
|
otherwise would be a boundary that does not exist.
|
|
|
|
**This follows from what was already decided rather than adding to it.**
|
|
[ADR 0004](0004-a-node-and-how-it-joins.md) says there is no authorisation between nodes — every
|
|
node is the operator's own, so a message from one is a message from them, and *the mesh boundary
|
|
is therefore the security boundary*. A user model inside that boundary would guard nothing: anyone
|
|
who could be stopped by it could equally read the node's key off the disk.
|
|
|
|
**The board is different, and the difference is the network.** A surface reachable by a browser
|
|
has to know who is asking, because the people reaching it are not, by construction, people with a
|
|
shell on the machine. **So the board delegates to an OAuth provider** — which is a module.
|
|
|
|
## What this does not change
|
|
|
|
**The identity provider is still not substrate** (ADR 0031). A *surface* delegating
|
|
authentication is not *the control plane* delegating it. The control plane runs, applies
|
|
declarations and reaches nodes with no identity provider in existence; only the board needs one,
|
|
and only to decide whose browser it is talking to.
|
|
|
|
The test is unchanged and still answers no: *does the control plane need it in order to run?*
|
|
|
|
## Consequences
|
|
|
|
**The board depends on a module, and says so.** An ordinary edge in the graph, which means the
|
|
board cannot come up before the provider it authenticates against — stated as a dependency rather
|
|
than discovered as an outage.
|
|
|
|
**Moving the identity provider takes the board with it.** During that module's own conversion the
|
|
board is unavailable, and that is acceptable: it is a surface, nothing depends on it, and a brief
|
|
interruption is the trade already accepted everywhere else. Nothing that keeps a service serving
|
|
goes through it.
|
|
|
|
**Anyone with a shell on a node has full authority there.** Written down rather than left implied,
|
|
because it is the sentence that decides who gets an account on a machine. The protection is the
|
|
machine's own login, and the overlay that keeps the machine unreachable from outside
|
|
([ADR 0007](0007-connectivity.md)).
|
|
|
|
**A node cannot be operated by somebody without a login on it.** Deliberate, and the cost of
|
|
having no user model: there is no way to give a person authority over one node without giving them
|
|
a shell there. If that is ever wanted, it is a new decision and not a gap in this one.
|
|
|
|
## References
|
|
|
|
- [ADR 0031](0031-the-control-plane-authenticates-nobody.md) — the control plane authenticates
|
|
nobody; this answers what it left open
|
|
- [ADR 0004](0004-a-node-and-how-it-joins.md) — no authorisation between nodes, and why the mesh
|
|
boundary is the security boundary
|
|
- [`03-DESIGN/01-to-be/11-a-board.md`](../03-DESIGN/01-to-be/11-a-board.md) — the surface this is
|
|
about
|