Files
hq/04-ISSUES/203-a-fresh-assignment-is-pushed-before-its-credential-exists/01-diagnosis.md
T

1.2 KiB

Diagnosis — 203

2026-10-03. Two acts, one effect. assign records the assignment and, at composition, every own-secrets entry a module declares gets a sealed value from the controller's Needed map — a value minted so the file exists, which for broker is a random secret, not a credential. The bus credential is composed only by module issue <module> --node <node> (cmd/mesh-controller/modules.go, issueOnTheNewBus → issueWith): it mints the bus user, records its hash, and seals the credential JSON into the same broker need. Nothing joins the two: push composes and sends whatever the need holds, and the only warning is the standing line listing every bus user without a minted credential, printed on every push regardless of what was just assigned.

Ruled out: the host (it wrote the file it was given, owned as asked); the runtime (it refused a file that is not JSON, correctly, and said so); the manifest (own-secrets.broker is the shape every module uses).

Owner: mesh-controller — the assign path. Fix direction: assigning a module that declares own-secrets.broker issues its credential in the same act, idempotently; a push of a module whose bus user is unminted is refused by name rather than sent with a placeholder.