Files
hq/04-ISSUES/078-a-delivered-secret-is-accepted-under-any-name/00-report.md
T

33 lines
1.4 KiB
Markdown

---
status: open
opened: 2026-09-21
located-in: [mesh-controller internal/inventory (secrets), mesh-controller cmd (secret accept)]
---
# 078 — A delivered secret is accepted under any name
## Symptom
`secret accept <node> <module> <name>` stores a value for a module under a name it does not
check against the module's manifest. A name the manifest no longer declares — an own secret that
became a requirement kept in the vault, or a name that never existed — is stored silently. The
row is dead: nothing reads it, the vault mints a value instead, and the operator believes they
delivered a secret the module is not using.
Found by review, not by a run: the whole-mesh bed delivered four such names after their modules
moved to the several-secrets vocabulary ([ADR 0094](../../02-DECISIONS/0094-a-module-may-hold-several-secrets-from-one-provider.md)),
and nothing said so.
## Why it matters beyond the instance
A silent acceptance is the shape of failure the mesh is built to refuse: an operator's action
that changes nothing and reports success. It hides every stale delivery, in beds and in operation
alike.
## What would close it
Acceptance is refused for a name the module's current manifest does not declare as an own
secret, with the names it does declare in the refusal. A unit test delivers under an undeclared
name and expects the refusal; the whole-mesh bed then fails loudly if a delivery goes stale
again.