State each provision's identity bound (hq issue 263)

Consumers were held to an S3 access key's 20 characters whatever they
required. Each provider now says what its backend keeps: minio 20,
PostgreSQL and MongoDB and DNS 63, Gitea 40, a mailbox 64, SQL Server 128,
Keycloak 255, unbounded where the store has no limit, and none for the
resolver and route provisions, which keep no name of their consumers.
Needs the controller that reads the field (mesh-controller, ADR 0225).
This commit is contained in:
jochen
2026-10-06 02:16:27 +02:00
parent cc2f19123a
commit 4769dadf63
15 changed files with 62 additions and 15 deletions
+5 -1
View File
@@ -5,7 +5,11 @@
"provides": [
{
"name": "public-dns",
"scope": "mesh"
"scope": "mesh",
"identity": {
"max": 63,
"in": "a DNS label"
}
}
],
"serves": {
+2 -1
View File
@@ -4,7 +4,8 @@
"provides": [
{
"name": "wildcard-resolution",
"scope": "mesh"
"scope": "mesh",
"identity": false
}
],
"requires": [
+5 -1
View File
@@ -182,7 +182,11 @@
"provides": [
{
"name": "npm-package-registry",
"scope": "mesh"
"scope": "mesh",
"identity": {
"max": 40,
"in": "a Gitea user name"
}
},
{
"name": "git",
+4 -1
View File
@@ -4,7 +4,10 @@
"provides": [
{
"name": "influxdb-api",
"scope": "mesh"
"scope": "mesh",
"identity": {
"in": "an InfluxDB v1 authorization"
}
}
],
"capabilities": [
+5 -1
View File
@@ -4,7 +4,11 @@
"provides": [
{
"name": "oidc-client",
"scope": "mesh"
"scope": "mesh",
"identity": {
"max": 255,
"in": "a Keycloak client id"
}
}
],
"requires": [
+5 -1
View File
@@ -537,7 +537,11 @@
"provides": [
{
"name": "smtp",
"scope": "mesh"
"scope": "mesh",
"identity": {
"max": 64,
"in": "a mailbox's local part"
}
}
],
"serves": {
+4 -1
View File
@@ -4,7 +4,10 @@
"provides": [
{
"name": "secret",
"scope": "mesh"
"scope": "mesh",
"identity": {
"in": "a vault entry"
}
}
],
"capabilities": [
+5 -1
View File
@@ -4,7 +4,11 @@
"provides": [
{
"name": "s3-bucket",
"scope": "mesh"
"scope": "mesh",
"identity": {
"max": 20,
"in": "an S3 access key"
}
}
],
"requires": [
+5 -1
View File
@@ -4,7 +4,11 @@
"provides": [
{
"name": "mongodb-database",
"scope": "mesh"
"scope": "mesh",
"identity": {
"max": 63,
"in": "a MongoDB database name"
}
}
],
"capabilities": [
+4 -1
View File
@@ -5,7 +5,10 @@
"provides": [
{
"name": "mqtt-topic",
"scope": "mesh"
"scope": "mesh",
"identity": {
"in": "a Mosquitto client and topic prefix"
}
}
],
"capabilities": [
+5 -1
View File
@@ -4,7 +4,11 @@
"provides": [
{
"name": "mssql-database",
"scope": "mesh"
"scope": "mesh",
"identity": {
"max": 128,
"in": "a SQL Server login and database name"
}
}
],
"capabilities": [
+5 -1
View File
@@ -4,7 +4,11 @@
"provides": [
{
"name": "postgres-database",
"scope": "mesh"
"scope": "mesh",
"identity": {
"max": 63,
"in": "a PostgreSQL role and database name"
}
}
],
"claims": [
+4 -1
View File
@@ -4,7 +4,10 @@
"provides": [
{
"name": "redis-cache",
"scope": "mesh"
"scope": "mesh",
"identity": {
"in": "a Redis ACL user and key prefix"
}
}
],
"requires": [
+2 -1
View File
@@ -8,7 +8,8 @@
"provides": [
{
"name": "route",
"scope": "mesh"
"scope": "mesh",
"identity": false
}
],
"serves": {
+2 -1
View File
@@ -8,7 +8,8 @@
"provides": [
{
"name": "route",
"scope": "mesh"
"scope": "mesh",
"identity": false
}
],
"serves": {