Files
hq/04-ISSUES/129-nothing-makes-a-machine-trust-the-meshs-authority/01-diagnosis.md
T
jschoubben 14be8576f8 Grooming: five issues were fixed and never closed, and one is not
088, 089, 120, 128 and 130 each name a commit that is on main and cites them —
the forge's address following a moved port, a route naming its endpoint, a
provisioner asking the backend what is there, the hosts file written into a
marked block, and undeclaring giving a unit back the state it was found in.
Each says it was closed by reading commits rather than by a run, so nobody
reads a green that was never measured.

129 stays located on purpose: ca-trust is merged and no machine holds it, so
the symptom it opened on is still true everywhere.
2026-09-29 22:25:25 +02:00

2.7 KiB

Diagnosis

2026-09-29.

What was ruled out

That something already carries the root and it is only misplaced. It does not. The authority serves its root at a path beside its ACME directory, and the one thing that fetches it — the route proxy — puts it in a directory of its own and hands it to one program. Nothing has ever written into a machine's trust store. Measured on three converged machines: the anchors present are the predecessor's authority and a developer tool's local root, and on the machines where the predecessor's was deliberately removed, every internal name fails verification.

That the private network could carry it, the way it carries the registry's trust. That is what the report proposed, and it was rejected on consideration rather than on difficulty (ADR 0147, option 1): being on the network is what makes the registry reachable and is therefore the right trigger there, while trusting an authority is a separate fact from being able to reach it. The anchor's directory and the command that refreshes the extracted bundles are also one operating system's difference, which is the host's half of the mesh and not the controller's.

That it needs a new host resource type. It does not, today. A file and a service say the whole of it, which the packet filter already proves. The primitive becomes the right answer when a second operating system is in play, and not before.

Where it belongs

A module in the catalogue: it requires internal-acme-ca, fetches the root over the mesh's own network, installs it as a trust anchor, refreshes the machine's bundles, and — because being unassigned stops its unit, and stopping the unit is what undoes it — takes both away again.

The owner is therefore mesh-catalog, module ca-trust, and nothing in the control plane.

The module exists, and this stays open until a machine holds it

2026-09-29. ca-trust is in the catalogue and merged (ADR 0147), and what it renders is checked in the control plane's own suite: the script fetches from the authority it was bound to, and the unit runs it both ways.

No machine has been assigned it, and nothing has verified a name because of it. The bed written for that cannot run (issue 146), and the live mesh has not been given the module. So the symptom this record opened on — every internal name failing verification on every machine — is still true everywhere, and the record stays located until it is not. Closing it on a module that exists would be closing it on an intention.