nodered says it reads its API token and admin password at start, so the mesh may rotate them (hq 180)

Both land in settings.js and the runtime's config file, and the containers that read them restart
on those files; a rotation is a new value and a restart. The broker credential says nothing yet: its
other party is the bus, and that rotation is the two-party form.
This commit is contained in:
2026-10-01 11:44:29 +02:00
parent 0966599c8a
commit 6b0164c2ba
+8 -2
View File
@@ -5,8 +5,14 @@
"flows.deployed" "flows.deployed"
], ],
"own-secrets": { "own-secrets": {
"admin": "${dir:mesh-state}/admin", "admin": {
"api-token": "${dir:mesh-state}/api-token", "path": "${dir:mesh-state}/admin",
"taken": "at-start"
},
"api-token": {
"path": "${dir:mesh-state}/api-token",
"taken": "at-start"
},
"broker": "${dir:mesh-state}/broker" "broker": "${dir:mesh-state}/broker"
}, },
"capabilities": [ "capabilities": [