Providers create the credential the mesh minted, sealing nothing (ADR 0053)

redis, postgres and minio adapters drop generatePassword + the returned credential:
each creates the resource under the login the mesh derived (`as`) with the password
the mesh minted (`p.password`). minio's client gains a secret-key argument so it sets
the mesh's secret rather than generating one. umami (analytics) is re-pointed at the
new contract too; its siteId return is a data-provision concern ADR 0053 scopes out.

Proven: mesh-lab provider-uses-mesh-credential green — redis creates the consumer's
login with the mesh's password, the consumer authenticates (PONG), no seal key set.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-05 00:27:37 +02:00
parent 550393b847
commit 3b03fcd8f7
5 changed files with 107 additions and 139 deletions
+8 -7
View File
@@ -10,7 +10,7 @@
// creation the MinIO admin REST API guards behind an encrypted payload `fetch` cannot form.
// This mirrors hal's MinIOClient/MinIOAdmin split, folded into one client the module builds from env.
import { createHash, createHmac, randomBytes } from "node:crypto";
import { createHash, createHmac } from "node:crypto";
import { execFile } from "node:child_process";
import { readFileSync, writeFileSync, unlinkSync } from "node:fs";
import { tmpdir } from "node:os";
@@ -205,14 +205,15 @@ export class MinioClient {
// --- admin plane (mc CLI) ------------------------------------------------
/**
* Create a service account scoped to one bucket and return its credential. The MinIO admin REST
* API encrypts this request with a key derived (Argon2) from the root secret, which node built-ins
* cannot reproduce — so, as hal did, the module drives the `mc` CLI, which the provisioner image
* bundles.
* Create a service account scoped to one bucket, under a given access key and secret key, and
* return the pair. The secret key is the mesh's — the mesh mints one password per consumer and
* hands a copy to both ends (novox/hq ADR 0053), so minio sets that as the secret rather than
* generating one the consumer could never learn. The MinIO admin REST API encrypts this request
* with a key derived (Argon2) from the root secret, which node built-ins cannot reproduce — so, as
* hal did, the module drives the `mc` CLI, which the runtime image bundles.
*/
async createAccessKey(bucket: string, accessKey: string): Promise<AccessKey> {
async createAccessKey(bucket: string, accessKey: string, secretKey: string): Promise<AccessKey> {
await this.ensureAlias();
const secretKey = randomBytes(20).toString("hex");
const policyPath = join(this.mcConfigDir, `policy-${accessKey}.json`);
writeFileSync(policyPath, bucketPolicy(bucket), { mode: 0o600 });
try {