Merge pull request 'Each uplink holder declares the manager it speaks for (hq ADR 0161)' (#206) from feat/each-uplink-holder-declares-the-manager-it-speaks-for into main
This commit was merged in pull request #206.
This commit is contained in:
@@ -1,9 +1,9 @@
|
|||||||
// mesh-vault's events entrypoint, loaded by the per-node tool host (the provisioner runs in the same
|
// mesh-vault's events entrypoint, loaded by the per-node tool host (the provisioner runs in the same
|
||||||
// process — ADR 0052). The lifecycle events are EMITTED from the provisioner, where custody
|
// process — ADR 0052). The lifecycle events are EMITTED from the provisioner, where custody
|
||||||
// actually changes (novox/hq ADR 0041/0042):
|
// actually changes (novox/hq ADR 0041/0042):
|
||||||
// mesh-vault.provisioned — a consumer was granted a secret
|
// module.mesh-vault.secret.provisioned — a consumer was granted a secret
|
||||||
// mesh-vault.rotated — that consumer's value changed (`rotate secret`)
|
// module.mesh-vault.secret.rotated — that consumer's value changed (`rotate secret`)
|
||||||
// mesh-vault.deprovisioned — the consumer went away and its secret was withdrawn
|
// module.mesh-vault.secret.deprovisioned — the consumer went away and its secret was withdrawn
|
||||||
// Here the vault reacts to them, keeping a lightweight audit line of who holds what and when it
|
// Here the vault reacts to them, keeping a lightweight audit line of who holds what and when it
|
||||||
// moved — the audit an owner of secrets is best placed to log. Fingerprints, never values.
|
// moved — the audit an owner of secrets is best placed to log. Fingerprints, never values.
|
||||||
|
|
||||||
@@ -16,15 +16,15 @@ interface SecretEvent {
|
|||||||
rotations?: number;
|
rotations?: number;
|
||||||
}
|
}
|
||||||
|
|
||||||
await on<SecretEvent>("provisioned", async (e) => {
|
await on<SecretEvent>("secret.provisioned", async (e) => {
|
||||||
console.log(`[mesh-vault] secret provisioned for ${e.body.as} on ${e.body.consumer} (${e.body.fingerprint})`);
|
console.log(`[mesh-vault] secret provisioned for ${e.body.as} on ${e.body.consumer} (${e.body.fingerprint})`);
|
||||||
});
|
});
|
||||||
|
|
||||||
await on<SecretEvent>("rotated", async (e) => {
|
await on<SecretEvent>("secret.rotated", async (e) => {
|
||||||
console.log(`[mesh-vault] secret rotated for ${e.body.as} — rotation ${e.body.rotations} (${e.body.fingerprint})`);
|
console.log(`[mesh-vault] secret rotated for ${e.body.as} — rotation ${e.body.rotations} (${e.body.fingerprint})`);
|
||||||
});
|
});
|
||||||
|
|
||||||
await on<SecretEvent>("deprovisioned", async (e) => {
|
await on<SecretEvent>("secret.deprovisioned", async (e) => {
|
||||||
console.log(`[mesh-vault] secret withdrawn from ${e.body.as}`);
|
console.log(`[mesh-vault] secret withdrawn from ${e.body.as}`);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -11,14 +11,14 @@
|
|||||||
"container-runtime"
|
"container-runtime"
|
||||||
],
|
],
|
||||||
"emits": [
|
"emits": [
|
||||||
"provisioned",
|
"secret.provisioned",
|
||||||
"rotated",
|
"secret.rotated",
|
||||||
"deprovisioned"
|
"secret.deprovisioned"
|
||||||
],
|
],
|
||||||
"consumes": [
|
"consumes": [
|
||||||
"mesh-vault.provisioned",
|
"mesh-vault.secret.provisioned",
|
||||||
"mesh-vault.rotated",
|
"mesh-vault.secret.rotated",
|
||||||
"mesh-vault.deprovisioned"
|
"mesh-vault.secret.deprovisioned"
|
||||||
],
|
],
|
||||||
"receives": {
|
"receives": {
|
||||||
"secret": "${dir:grants}/mesh.json"
|
"secret": "${dir:grants}/mesh.json"
|
||||||
@@ -98,11 +98,5 @@
|
|||||||
"from": "Dockerfile"
|
"from": "Dockerfile"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
}
|
||||||
"claims": [
|
|
||||||
{
|
|
||||||
"name": "mesh-vault",
|
|
||||||
"scope": "mesh"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -43,6 +43,6 @@ runProvisioner("secret", {
|
|||||||
async remove(p: { as: string }): Promise<void> {
|
async remove(p: { as: string }): Promise<void> {
|
||||||
if (!ledger.withdraw(p.as)) return;
|
if (!ledger.withdraw(p.as)) return;
|
||||||
console.log(`[mesh-vault] withdrawn: ${p.as}`);
|
console.log(`[mesh-vault] withdrawn: ${p.as}`);
|
||||||
await announce("deprovisioned", { as: p.as });
|
await announce("secret.deprovisioned", { as: p.as });
|
||||||
},
|
},
|
||||||
});
|
});
|
||||||
|
|||||||
Reference in New Issue
Block a user