The status warning names 49 users; 48 are modules that never speak on the bus, and the one real fault, a declared broker secret filled with a generated value, looked the same as the rest.
3.2 KiB
status, opened, located-in, fixed-by, amended-design
| status | opened | located-in | fixed-by | amended-design |
|---|---|---|---|---|
| open | 2026-10-02 |
195 — Every assigned module is counted as a bus user without a credential, and the real gaps are lost in the count
What was observed
status, and plan for any machine, open with one line before anything else:
the bus's user list leaves out 49 user(s) the mesh has minted no credential for: <node>.<module>, …
Each is a user that cannot connect until one is issued
The 49 are spread over four machines and name 26 distinct modules. Checked against the catalogue on 2026-10-02:
| what the module's definition says | modules |
|---|---|
declares an own secret named broker |
1 — the route proxy, which needed a bus account for issue 191 |
declares no broker secret, and emits, consumes and serves nothing on the bus |
17 — the packet filter, the intrusion filter, the ssh daemon, the resolver configuration, the certificate authority, the broker itself and others |
declares no broker secret, and emits events |
1 |
| not in this catalogue, so not checked | 7 |
So the line counts every module assigned anywhere as a bus user. For almost all of them that is not a
missing credential. A module with no broker secret has nowhere to receive one, and the mesh already
says an account nothing reads is an orphan (issue 078).
Two real gaps sit inside the count and cannot be told from the noise:
- A declared
brokersecret was filled with a value that is not an account. Before its account was issued, the route proxy's plan on both machines already carried a sealedbrokerfile, while the same status line said no credential had been minted for it. A push had made the declared secret the way it makes any own secret. The module would have started with a credential the bus does not know, and nothing would have said why. It was found only because the account was being issued by hand. - A module that emits events declares no way to reach the bus. Its events can go nowhere, and no check refuses that.
Why it matters
A warning that is always on is read as never on. The line names 49 users on every status and every
plan. An operator, or an agent, learns to scroll past it. The one entry that was a real fault looked
exactly like the 48 that were not.
The fault that was real is the silent kind. A module whose broker credential is a generated value starts, fails to authenticate, and reports that three layers away from the cause. That is the failure the composition already refuses for a secret that was never made at all ("declared and not made"). Here a value was made, so the refusal never fired.
Open questions
- Should a bus user be composed for a module that declares no
brokersecret at all? If not, the line shrinks to the modules that can actually use an account. - Is a
brokersecret ever correctly made by the generic generator? If not, should composition refuse a declaredbrokeruntil it is issued, or should the mesh issue it as part of placing the module? - Should a module that emits, consumes or serves on the bus be refused when it declares no
brokersecret?