19 lines
1.2 KiB
Markdown
19 lines
1.2 KiB
Markdown
# Diagnosis — 203
|
|
|
|
**2026-10-03.** Two acts, one effect. `assign` records the assignment and, at composition, every
|
|
`own-secrets` entry a module declares gets a sealed value from the controller's `Needed` map — a
|
|
value minted so the file exists, which for `broker` is a random secret, not a credential. The bus
|
|
credential is composed only by `module issue <module> --node <node>` (cmd/mesh-controller/modules.go,
|
|
`issueOnTheNewBus` → `issueWith`): it mints the bus user, records its hash, and seals the credential
|
|
JSON into the same `broker` need. Nothing joins the two: `push` composes and sends whatever the need
|
|
holds, and the only warning is the standing line listing every bus user without a minted credential,
|
|
printed on every push regardless of what was just assigned.
|
|
|
|
Ruled out: the host (it wrote the file it was given, owned as asked); the runtime (it refused a file
|
|
that is not JSON, correctly, and said so); the manifest (`own-secrets.broker` is the shape every
|
|
module uses).
|
|
|
|
**Owner:** mesh-controller — the assign path. **Fix direction:** assigning a module that declares
|
|
`own-secrets.broker` issues its credential in the same act, idempotently; a push of a module whose bus
|
|
user is unminted is refused by name rather than sent with a placeholder.
|