The vault's claim and its own event names return

The uplink branch was split from the vault's with the vault's files reset to a main that did not yet
hold #205; merging it afterwards took the older vault definition along (no claim, the refused event
names), and the vault could not be built. Restored to #205's state.
This commit is contained in:
2026-10-01 17:19:05 +02:00
parent 5ebc89d89d
commit 89e0dde9e0
3 changed files with 20 additions and 14 deletions
+6 -6
View File
@@ -1,9 +1,9 @@
// mesh-vault's events entrypoint, loaded by the per-node tool host (the provisioner runs in the same // mesh-vault's events entrypoint, loaded by the per-node tool host (the provisioner runs in the same
// process — ADR 0052). The lifecycle events are EMITTED from the provisioner, where custody // process — ADR 0052). The lifecycle events are EMITTED from the provisioner, where custody
// actually changes (novox/hq ADR 0041/0042): // actually changes (novox/hq ADR 0041/0042):
// module.mesh-vault.secret.provisioned — a consumer was granted a secret // mesh-vault.provisioned — a consumer was granted a secret
// module.mesh-vault.secret.rotated — that consumer's value changed (`rotate secret`) // mesh-vault.rotated — that consumer's value changed (`rotate secret`)
// module.mesh-vault.secret.deprovisioned — the consumer went away and its secret was withdrawn // mesh-vault.deprovisioned — the consumer went away and its secret was withdrawn
// Here the vault reacts to them, keeping a lightweight audit line of who holds what and when it // Here the vault reacts to them, keeping a lightweight audit line of who holds what and when it
// moved — the audit an owner of secrets is best placed to log. Fingerprints, never values. // moved — the audit an owner of secrets is best placed to log. Fingerprints, never values.
@@ -16,15 +16,15 @@ interface SecretEvent {
rotations?: number; rotations?: number;
} }
await on<SecretEvent>("secret.provisioned", async (e) => { await on<SecretEvent>("provisioned", async (e) => {
console.log(`[mesh-vault] secret provisioned for ${e.body.as} on ${e.body.consumer} (${e.body.fingerprint})`); console.log(`[mesh-vault] secret provisioned for ${e.body.as} on ${e.body.consumer} (${e.body.fingerprint})`);
}); });
await on<SecretEvent>("secret.rotated", async (e) => { await on<SecretEvent>("rotated", async (e) => {
console.log(`[mesh-vault] secret rotated for ${e.body.as} — rotation ${e.body.rotations} (${e.body.fingerprint})`); console.log(`[mesh-vault] secret rotated for ${e.body.as} — rotation ${e.body.rotations} (${e.body.fingerprint})`);
}); });
await on<SecretEvent>("secret.deprovisioned", async (e) => { await on<SecretEvent>("deprovisioned", async (e) => {
console.log(`[mesh-vault] secret withdrawn from ${e.body.as}`); console.log(`[mesh-vault] secret withdrawn from ${e.body.as}`);
}); });
+12 -6
View File
@@ -11,14 +11,14 @@
"container-runtime" "container-runtime"
], ],
"emits": [ "emits": [
"secret.provisioned", "provisioned",
"secret.rotated", "rotated",
"secret.deprovisioned" "deprovisioned"
], ],
"consumes": [ "consumes": [
"mesh-vault.secret.provisioned", "mesh-vault.provisioned",
"mesh-vault.secret.rotated", "mesh-vault.rotated",
"mesh-vault.secret.deprovisioned" "mesh-vault.deprovisioned"
], ],
"receives": { "receives": {
"secret": "${dir:grants}/mesh.json" "secret": "${dir:grants}/mesh.json"
@@ -98,5 +98,11 @@
"from": "Dockerfile" "from": "Dockerfile"
} }
] ]
},
"claims": [
{
"name": "mesh-vault",
"scope": "mesh"
} }
]
} }
+1 -1
View File
@@ -43,6 +43,6 @@ runProvisioner("secret", {
async remove(p: { as: string }): Promise<void> { async remove(p: { as: string }): Promise<void> {
if (!ledger.withdraw(p.as)) return; if (!ledger.withdraw(p.as)) return;
console.log(`[mesh-vault] withdrawn: ${p.as}`); console.log(`[mesh-vault] withdrawn: ${p.as}`);
await announce("secret.deprovisioned", { as: p.as }); await announce("deprovisioned", { as: p.as });
}, },
}); });