Add mesh-vault; redis, postgres and lavinmq take their passwords from files #30

Merged
jschoubben merged 1 commits from feat/secrets-vault into main 2026-09-21 08:03:13 +00:00
Owner

novox/hq ADR 0085 (amended), design 24. Merge second of five, after mesh-controller (needs its keeps field and secret provision handling).

  • modules/mesh-vault: provides secret; a ledger of who holds one and its fingerprint, tools secret_holders / secret_verify / secret_export that never return a value; keeps the operator-sealed export at /var/lib/mesh-vault/root.
  • redis: its own password becomes a secret it requires from the vault; the server restarts on its config so rotation reaches it.
  • postgres: the store reads its superuser from /var/lib/postgres/superuser.secret (genesis writes it, the mesh keeps it); lavinmq: the admin password is an own secret read from a file, not a literal in the runtime's env.

Proven by mesh-lab assigned-vault.test.ts and one-node-mesh.test.ts on this branch set.

novox/hq ADR 0085 (amended), design 24. Merge second of five, after mesh-controller (needs its `keeps` field and `secret` provision handling). - `modules/mesh-vault`: provides `secret`; a ledger of who holds one and its fingerprint, tools `secret_holders` / `secret_verify` / `secret_export` that never return a value; keeps the operator-sealed export at `/var/lib/mesh-vault/root`. - redis: its own password becomes a `secret` it requires from the vault; the server restarts on its config so rotation reaches it. - postgres: the store reads its superuser from `/var/lib/postgres/superuser.secret` (genesis writes it, the mesh keeps it); lavinmq: the admin password is an own secret read from a file, not a literal in the runtime's env. Proven by mesh-lab `assigned-vault.test.ts` and `one-node-mesh.test.ts` on this branch set.
jschoubben added 1 commit 2026-09-21 07:30:02 +00:00
mesh-vault provides `secret` (novox/hq ADR 0085, design 24). The value is
the pair credential the controller mints — the vault holds no copy, only a
ledger of who holds one, its fingerprint and every rotation, and two tools that
answer by fingerprint and never by value. Rotation is `rotate secret`,
unchanged machinery pointed at a secret with an owner (design 13). Named in the
mesh's own namespace, beside mesh-controller and mesh-catalog, because it is
the mesh's own code rather than wrapped software.

redis is the first consumer: its own password stops being an own-secret nothing
could rotate and becomes a `secret` it requires, read from the same file into
the same hole. The server now restarts on its config, or it would keep the
password it started with through every rotation (playbook 06).
jschoubben merged commit d03520f4ed into main 2026-09-21 08:03:13 +00:00
jschoubben deleted branch feat/secrets-vault 2026-09-21 08:03:13 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#30