Files
hq/02-DECISIONS/0031-the-control-plane-authenticates-nobody.md
T
jschoubben e3934e4449 The control plane authenticates nobody, so identity is a module
Closes the last open question about what the substrate contains. 0006
left an identity provider conditional — substrate only if the control
plane delegated authentication — and said the decision had not been
taken. It is now: it delegates to nothing.

The conditional was never about machines. A node proves itself with a
keypair it generated over a broker account issued at enrolment, and
declarations are verified by signature; none of that involves an
identity provider. It was only ever about whether a person signing in to
a mesh surface would be authenticated by something else.

So the substrate is three — a relational store, a message bus, an image
registry — and with 0028 having removed the object store, no member is
conditional and every one is there for the same reason.

It does not settle how a person signs in to a surface, deliberately.
What is settled is that whatever answers that is not something which
must exist before the mesh does, so it can be decided late or replaced —
which being substrate would have prevented.
2026-08-31 20:18:03 +02:00

3.4 KiB

topic, status, date, deciders, reconstructed, extends
topic status date deciders reconstructed extends
the tiers accepted 2026-08-31 jochen false 02-DECISIONS/0006-the-substrate-and-the-control-plane.md

31. The control plane authenticates nobody, so identity is a module

Context

ADR 0006 left one member of the substrate conditional, and said exactly why:

role product
identity provider — conditional: substrate only if the control plane delegates authentication, which is undecided

07-the-substrate.md carried it as an open question — whether identity is the fifth — noting it followed from a decision nobody had taken.

The decision is taken: the control plane does not delegate authentication. There is no mesh identity provider.

Nothing in the mesh's own machinery ever needed one. A node proves itself with a keypair it generated, over a broker account issued at enrolment (ADR 0004). Declarations are verified by signature. None of that touches an identity provider, and the conditional was never about machines — it was only ever about whether a person signing in to a mesh surface would be authenticated by something else.

Decision

Identity is a module, like the mail system and the forge. It runs on the mesh, not of it (ADR 0001) — a provider other modules require, which is the ordinary shape and needs nothing new to express.

So the substrate is three, and no longer conditional: a relational store, a message bus, and an image registry. Together with ADR 0028, which removed the object store, the list is settled and every member is there for the same reason — the control plane needs it and cannot ask itself for it.

A mesh that wants no identity provider runs none. That is now expressible, and was not while it sat in the substrate as a maybe.

Consequences

The last open question about substrate membership is closed. Both halves of ADR 0006's test now have an answer for every candidate, and the answer for identity is the control plane does not need it.

It does not settle how a person signs in to a mesh surface, and that is deliberately left open. What is settled is that whatever answers it is not part of what must exist before the mesh does — so it can be decided late, changed, or replaced, which is precisely what being substrate would have prevented.

It becomes a real test of the module graph. An identity provider is a module that other modules require — the object store already consumes it — so it exercises the provider chain more seriously than anything ported so far, where the provider was written alongside its consumer.

Ordering follows from it rather than from preference. Anything requiring identity has to move after it, which is a dependency the graph can state rather than something a person has to remember.

References

  • ADR 0006 — the conditional this closes
  • ADR 0028 — the other member removed, and the test applied properly
  • ADR 0004 — how a node proves itself, which needs none of this