2.2 KiB
status, opened, located-in, fixed-by, amended-design
| status | opened | located-in | fixed-by | amended-design | ||
|---|---|---|---|---|---|---|
| located | 2026-09-21 |
|
A served fact made at first start cannot be served, so the catalogue's authority cannot start
Symptom, as observed
The catalogue's certificate authority module declares its root certificate, its root key and that key's password as its own secrets, and writes each into a file the container is told to initialise from. The mesh mints an own secret as random bytes. Random bytes are not a certificate: as written, the authority cannot initialise, and no bed has ever raised it — the whole-mesh bed that names it has not run since it was converted. Found while converting the route-forwarding bed to the catalogue's proxy, which requires the authority beside it.
The authority can make its own root at first start — the certificate bed raises it that way and
it issues within a second. What it cannot do then is tell the mesh what that root is: a
consumer of acme-ca is given ${bound:acme-ca:root} from the provider's serves, which is
written in the manifest before anything runs.
Why it matters beyond this instance
- Two kinds of secret the vocabulary does not distinguish. A value the mesh may invent (a password) and a value only the module can produce (a key pair, a certificate) are both "own secrets", and the mesh invents both.
- A served fact that exists only after first start has no way into a binding. Anything a module generates and its consumers must trust — a root, a public key, a fingerprint — is in the same position.
- Every consumer of
acme-ca, which today is the route proxy, is blocked with it.
What would close it
Either a module may say a secret is made by the module — the mesh reserves the name, the module writes the value once, the mesh takes custody of it and delivers it where it is bound — or a served fact may be contributed at run time by the provider's runtime rather than written in its manifest. The first is the smaller change and covers the root certificate; the second is what a fingerprint or a public key wants. Decided, then the authority raised in the lab beside the proxy, which is the route-forwarding bed's conversion.