Files
hq/04-ISSUES/071-the-foundation-is-raised-with-fixed-credentials/00-report.md
T
jschoubben 1bce3f33a8 Designs 07 and 21 and issue 071: genesis now makes the root secrets
The installer half of the amended ADR 0085 is built and proven by the
genesis bed's root-secrets step; the foundation design closes its open item
and the installation design says what the installer does and what it still
cannot check.
2026-09-21 00:50:56 +02:00

2.5 KiB

status, opened, located-in, fixed-by, amended-design
status opened located-in fixed-by amended-design
resolved 2026-09-20
mesh-host internal/bootstrap
mesh-host examples/foundation-first-node.lock
mesh-host feat/secrets-vault (ee0c8b8, genesis root credentials + operator key + vault); mesh-controller feat/secrets-vault (e140ed5, 565f144); mesh-catalog feat/secrets-vault; proven by the one-node genesis bed step V5 03-DESIGN/01-to-be/24-the-secrets-vault.md

The foundation is raised with fixed credentials, and they stay

Symptom, as observed

The foundation bundle raises the store with a superuser password that is the literal word bootstrap, and the broker with its image's default administrator, guest / guest. The installer then carries both into the mesh through secret accept, sealed to the control-node's key, marked accepted so the mesh will never replace them — which is correct for a credential that already created the databases, and means the well-known value is now permanent.

Every module's own secret minted afterwards is random and sealed. The two that everything else rests on are not random, and there is no operator key at genesis for anything to be sealed to.

Why it matters beyond this instance

  • These are the root secrets. A mesh whose store superuser is a published constant is a mesh whose every provisioned credential is one connection away, from any node that can reach 5432.
  • It is invisible. secret accept reports the value as sealed to the machine and unreadable by the mesh, which is true, and says nothing about where it came from.
  • Rotation cannot fix it later. An accepted own secret is never remade by the mesh, and there is no rotate for own secrets; the only path is to change it on the server by hand and accept it again, which is the manual rotation the as-is design records as having taken services down.

What closes it

ADR 0085, amended, and design 24: genesis makes the operator key first, mints real credentials for the store and broker before the bundle raises them (or changes them on the running servers before handing over), accepts those, and installs mesh-vault so the operator-sealed export exists from the first push. Built on feat/secrets-vault across mesh-host, mesh-controller and mesh-catalog, and proven by the one-node genesis bed: the template's password is refused by the store, the export and the vault's copy hold no plaintext, and the superuser recovered off the mesh with the operator key opens the store.