Files
hq/04-ISSUES/076-a-served-fact-made-at-first-start-cannot-be-served/01-diagnosis.md
T

1.7 KiB

Diagnosis — 2026-09-21

  1. The certificate bed already raised the same authority image with no root supplied, and it made its own root and issued within a second. The manifest's three minted "secrets" were not needed by the authority; they were needed by the consumer, which was handed the root as a served fact.
  2. Of the three ways to get a fact made at first start to a consumer, two need a channel from a node up to the mesh that does not exist. The third needs nothing new: the provider serves the fact at a path, and the consumer fetches it over the mesh network in a gate before it starts.

Located in: the two manifests. Decided in ADR 0098.

Proven the same day: the route-forwarding bed raises the authority, the proxy and a consumer from the catalogue on one node and serves a public name through the proxy. Two things the run taught, both about the bed rather than the decision:

  • The authority certifies itself for the machine's private-network address, which is what a consumer on any node dials. A machine raised from the foundation bundle has no such address until it is placed on the overlay, so a bed must place it first — as a hub of one, the way a real first node is.
  • With the overlay's networking and the three modules in one push, the proxy's fetch of the roots timed out at the private-network address; with the overlay converged first and the modules pushed after, it passes. Whether that was the order of application within a push or the filter closing the interface until it was derived was not isolated. A consumer whose first start dials a provider assumes the provider's network is already there; the bed makes it so.