46 lines
2.6 KiB
Markdown
46 lines
2.6 KiB
Markdown
---
|
|
status: resolved
|
|
opened: 2026-09-21
|
|
located-in: [mesh-catalog modules/step-ca, mesh-catalog modules/route-proxy]
|
|
fixed-by: ADR 0098; mesh-catalog multiple-fixes (the authority makes its own root and serves it; the proxy fetches it through a gate); proven by the route-forwarding bed
|
|
amended-design: 03-DESIGN/01-to-be/08-connectivity.md
|
|
---
|
|
|
|
# A served fact made at first start cannot be served, so the catalogue's authority cannot start
|
|
|
|
## Symptom, as observed
|
|
|
|
The catalogue's certificate authority module declares its root certificate, its root key and
|
|
that key's password as its own secrets, and writes each into a file the container is told to
|
|
initialise from. An own secret nobody delivers is minted by the mesh as random bytes, and random
|
|
bytes are not a certificate: issued that way, the authority cannot initialise. It could be
|
|
raised by an operator making a root with openssl and delivering all three through `secret
|
|
accept` — the whole-mesh bed did exactly that, and has not run since it was converted — but a
|
|
module that only starts once a person has hand-made its key material is not a module a mesh
|
|
can raise. Found while converting the route-forwarding bed to the catalogue's proxy, which
|
|
requires the authority beside it.
|
|
|
|
The authority can make its own root at first start — the certificate bed raises it that way and
|
|
it issues within a second. What it cannot do then is tell the mesh what that root is: a
|
|
consumer of `acme-ca` is given `${bound:acme-ca:root}` from the provider's `serves`, which is
|
|
written in the manifest before anything runs.
|
|
|
|
## Why it matters beyond this instance
|
|
|
|
- **Two kinds of secret the vocabulary does not distinguish.** A value the mesh may invent (a
|
|
password) and a value only the module can produce (a key pair, a certificate) are both
|
|
"own secrets", and the mesh invents both.
|
|
- **A served fact that exists only after first start** has no way into a binding. Anything a
|
|
module generates and its consumers must trust — a root, a public key, a fingerprint — is in
|
|
the same position.
|
|
- Every consumer of `acme-ca`, which today is the route proxy, is blocked with it.
|
|
|
|
## What would close it
|
|
|
|
Either a module may say a secret is *made by the module* — the mesh reserves the name, the
|
|
module writes the value once, the mesh takes custody of it and delivers it where it is bound —
|
|
or a served fact may be *contributed at run time* by the provider's runtime rather than written
|
|
in its manifest. The first is the smaller change and covers the root certificate; the second is
|
|
what a fingerprint or a public key wants. Decided, then the authority raised in the lab beside
|
|
the proxy, which is the route-forwarding bed's conversion.
|