nodered says it reads its API token and admin password at start, so the mesh may rotate them (hq 180) #201

Merged
mesh-admin merged 1 commits from feat/nodered-says-how-its-secrets-are-taken into main 2026-10-01 09:45:32 +00:00
Contributor

First definition to say taken (mesh-controller #183, hq issue 180). Both secrets land in settings.js and the runtime's config file, and the containers that read them restart on those files, so a rotation is a new value and a restart. The broker credential says nothing yet: its other party is the bus, and that rotation is the two-party form.

Merge after the controller from #183 is running — the older one refuses the object form at registration (module check passes under the new one).

First definition to say `taken` (mesh-controller #183, hq issue 180). Both secrets land in `settings.js` and the runtime's config file, and the containers that read them restart on those files, so a rotation is a new value and a restart. The broker credential says nothing yet: its other party is the bus, and that rotation is the two-party form. **Merge after the controller from #183 is running** — the older one refuses the object form at registration (`module check` passes under the new one).
mesh-admin added 1 commit 2026-10-01 09:45:01 +00:00
Both land in settings.js and the runtime's config file, and the containers that read them restart
on those files; a rotation is a new value and a restart. The broker credential says nothing yet: its
other party is the bus, and that rotation is the two-party form.
mesh-admin merged commit 1712670610 into main 2026-10-01 09:45:32 +00:00
mesh-admin deleted branch feat/nodered-says-how-its-secrets-are-taken 2026-10-01 09:45:33 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#201