Files
hq/04-ISSUES/078-a-delivered-secret-is-accepted-under-any-name/00-report.md
T

1.4 KiB

status, opened, located-in
status opened located-in
open 2026-09-21
mesh-controller internal/inventory (secrets)
mesh-controller cmd (secret accept)

078 — A delivered secret is accepted under any name

Symptom

secret accept <node> <module> <name> stores a value for a module under a name it does not check against the module's manifest. A name the manifest no longer declares — an own secret that became a requirement kept in the vault, or a name that never existed — is stored silently. The row is dead: nothing reads it, the vault mints a value instead, and the operator believes they delivered a secret the module is not using.

Found by review, not by a run: the whole-mesh bed delivered four such names after their modules moved to the several-secrets vocabulary (ADR 0094), and nothing said so.

Why it matters beyond the instance

A silent acceptance is the shape of failure the mesh is built to refuse: an operator's action that changes nothing and reports success. It hides every stale delivery, in beds and in operation alike.

What would close it

Acceptance is refused for a name the module's current manifest does not declare as an own secret, with the names it does declare in the refusal. A unit test delivers under an undeclared name and expects the refusal; the whole-mesh bed then fails loudly if a delivery goes stale again.