From 2e96d2f67d20a9efa66f67d7d727fef1da63f4d4 Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 1 Oct 2026 16:52:47 +0200 Subject: [PATCH] This branch carries the uplink capabilities alone (hq ADR 0161 rule 3); merges once every machine running a holder has reported uplink- --- modules/mesh-vault/index.ts | 12 ++++++------ modules/mesh-vault/module.json | 20 +++++++------------- modules/mesh-vault/provisioner/index.ts | 2 +- 3 files changed, 14 insertions(+), 20 deletions(-) diff --git a/modules/mesh-vault/index.ts b/modules/mesh-vault/index.ts index 80f74f3..540a780 100644 --- a/modules/mesh-vault/index.ts +++ b/modules/mesh-vault/index.ts @@ -1,9 +1,9 @@ // mesh-vault's events entrypoint, loaded by the per-node tool host (the provisioner runs in the same // process — ADR 0052). The lifecycle events are EMITTED from the provisioner, where custody // actually changes (novox/hq ADR 0041/0042): -// mesh-vault.provisioned — a consumer was granted a secret -// mesh-vault.rotated — that consumer's value changed (`rotate secret`) -// mesh-vault.deprovisioned — the consumer went away and its secret was withdrawn +// module.mesh-vault.secret.provisioned — a consumer was granted a secret +// module.mesh-vault.secret.rotated — that consumer's value changed (`rotate secret`) +// module.mesh-vault.secret.deprovisioned — the consumer went away and its secret was withdrawn // Here the vault reacts to them, keeping a lightweight audit line of who holds what and when it // moved — the audit an owner of secrets is best placed to log. Fingerprints, never values. @@ -16,15 +16,15 @@ interface SecretEvent { rotations?: number; } -await on("provisioned", async (e) => { +await on("secret.provisioned", async (e) => { console.log(`[mesh-vault] secret provisioned for ${e.body.as} on ${e.body.consumer} (${e.body.fingerprint})`); }); -await on("rotated", async (e) => { +await on("secret.rotated", async (e) => { console.log(`[mesh-vault] secret rotated for ${e.body.as} — rotation ${e.body.rotations} (${e.body.fingerprint})`); }); -await on("deprovisioned", async (e) => { +await on("secret.deprovisioned", async (e) => { console.log(`[mesh-vault] secret withdrawn from ${e.body.as}`); }); diff --git a/modules/mesh-vault/module.json b/modules/mesh-vault/module.json index 29e17a3..991e237 100644 --- a/modules/mesh-vault/module.json +++ b/modules/mesh-vault/module.json @@ -11,14 +11,14 @@ "container-runtime" ], "emits": [ - "provisioned", - "rotated", - "deprovisioned" + "secret.provisioned", + "secret.rotated", + "secret.deprovisioned" ], "consumes": [ - "mesh-vault.provisioned", - "mesh-vault.rotated", - "mesh-vault.deprovisioned" + "mesh-vault.secret.provisioned", + "mesh-vault.secret.rotated", + "mesh-vault.secret.deprovisioned" ], "receives": { "secret": "${dir:grants}/mesh.json" @@ -98,11 +98,5 @@ "from": "Dockerfile" } ] - }, - "claims": [ - { - "name": "mesh-vault", - "scope": "mesh" - } - ] + } } diff --git a/modules/mesh-vault/provisioner/index.ts b/modules/mesh-vault/provisioner/index.ts index 37808a1..ad0872c 100644 --- a/modules/mesh-vault/provisioner/index.ts +++ b/modules/mesh-vault/provisioner/index.ts @@ -43,6 +43,6 @@ runProvisioner("secret", { async remove(p: { as: string }): Promise { if (!ledger.withdraw(p.as)) return; console.log(`[mesh-vault] withdrawn: ${p.as}`); - await announce("deprovisioned", { as: p.as }); + await announce("secret.deprovisioned", { as: p.as }); }, });