The vault's events are its own: provisioned, rotated, deprovisioned

A module publishes under its own name only; secret.provisioned read as another module's event and the
builder refused the vault's definition today, so the seat claim could not be built. The three events lose
the prefix; nothing outside the vault listens for the old names.
This commit is contained in:
2026-10-01 16:50:56 +02:00
parent 966fed1829
commit 8368697744
2 changed files with 12 additions and 12 deletions
+6 -6
View File
@@ -1,9 +1,9 @@
// mesh-vault's events entrypoint, loaded by the per-node tool host (the provisioner runs in the same
// process — ADR 0052). The lifecycle events are EMITTED from the provisioner, where custody
// actually changes (novox/hq ADR 0041/0042):
// module.mesh-vault.secret.provisioned — a consumer was granted a secret
// module.mesh-vault.secret.rotated — that consumer's value changed (`rotate secret`)
// module.mesh-vault.secret.deprovisioned — the consumer went away and its secret was withdrawn
// mesh-vault.provisioned — a consumer was granted a secret
// mesh-vault.rotated — that consumer's value changed (`rotate secret`)
// mesh-vault.deprovisioned — the consumer went away and its secret was withdrawn
// Here the vault reacts to them, keeping a lightweight audit line of who holds what and when it
// moved — the audit an owner of secrets is best placed to log. Fingerprints, never values.
@@ -16,15 +16,15 @@ interface SecretEvent {
rotations?: number;
}
await on<SecretEvent>("secret.provisioned", async (e) => {
await on<SecretEvent>("provisioned", async (e) => {
console.log(`[mesh-vault] secret provisioned for ${e.body.as} on ${e.body.consumer} (${e.body.fingerprint})`);
});
await on<SecretEvent>("secret.rotated", async (e) => {
await on<SecretEvent>("rotated", async (e) => {
console.log(`[mesh-vault] secret rotated for ${e.body.as} — rotation ${e.body.rotations} (${e.body.fingerprint})`);
});
await on<SecretEvent>("secret.deprovisioned", async (e) => {
await on<SecretEvent>("deprovisioned", async (e) => {
console.log(`[mesh-vault] secret withdrawn from ${e.body.as}`);
});
+6 -6
View File
@@ -11,14 +11,14 @@
"container-runtime"
],
"emits": [
"secret.provisioned",
"secret.rotated",
"secret.deprovisioned"
"provisioned",
"rotated",
"deprovisioned"
],
"consumes": [
"mesh-vault.secret.provisioned",
"mesh-vault.secret.rotated",
"mesh-vault.secret.deprovisioned"
"mesh-vault.provisioned",
"mesh-vault.rotated",
"mesh-vault.deprovisioned"
],
"receives": {
"secret": "${dir:grants}/mesh.json"