46 lines
2.3 KiB
Markdown
46 lines
2.3 KiB
Markdown
---
|
|
status: located
|
|
opened: 2026-10-02
|
|
located-in:
|
|
- mesh-controller
|
|
fixed-by:
|
|
amended-design:
|
|
---
|
|
|
|
# 203 — A fresh assignment is pushed before its credential exists, and the runtime crash-loops
|
|
|
|
## What was observed
|
|
|
|
2026-10-02, the first live assignment of the node tools runtime (to-be 38 WP3). `assign` put the
|
|
module on a machine and `push` sent the declaration. The host applied everything: the bundle unpacked,
|
|
the unit written and started, the module's `broker` secret file written and owned by the operator
|
|
account. The runtime then restarted thirteen times in a minute:
|
|
|
|
```
|
|
mesh-tools: cannot read the broker credential at …/broker: SyntaxError: Unexpected token 'O',
|
|
"Oj6j2Ssa-v"... is not valid JSON
|
|
```
|
|
|
|
The file held a 40-byte random secret, not a bus credential. The push's own output had said why,
|
|
one line among forty: *the bus's user list leaves out … `<node>.node-tools`. Each is a user that cannot
|
|
connect until one is issued.* The credential exists only after `module issue <module> --node <node>`,
|
|
a separate act; a second push then carried the real credential and the runtime came up. The same
|
|
sequence repeated on the next two machines, by hand, in the right order.
|
|
|
|
## Why it matters beyond this instance
|
|
|
|
Every module that speaks on the bus declares an `own-secrets.broker`; the mesh seals *something*
|
|
there on assignment and the real credential only on issue. So the first push of any fresh assignment
|
|
delivers a process that cannot authenticate and will crash-loop until a person runs a second verb and
|
|
a second push. Nothing refuses the first push, and the warning is a line in a long list that is
|
|
printed on every push regardless. The design says the mesh issues an assignment's subjects and the
|
|
runtime serves what it is issued ([ADR 0160](../../02-DECISIONS/0160-the-mesh-issues-an-assignments-subjects-and-a-runtime-serves-what-it-is-issued.md));
|
|
an assignment whose credential is not issued is half an assignment, and the mesh lets it through.
|
|
|
|
## Questions HQ must answer
|
|
|
|
- Is issuing the credential part of assigning, so `assign` mints it, or must a push refuse a module
|
|
whose bus user is unminted, naming the verb?
|
|
- Is a placeholder sealed where a credential belongs ever right, or should the resource be absent
|
|
until the credential exists, so the host never writes a file the process cannot read?
|