novox/hq ADR 0086. Merge second of four, after mesh-controller (needs secrets-owner and the env rule).
mesh-controller: mounts its six own secrets, names them with _FILE twins, and owns the files as 65534 — no credential of its own reaches its environment.
35 containers in 24 modules carry secrets-in-environment with a reason; converting each where its software accepts a path is the per-module work of issue 041.
Proven by the one-node genesis bed on this branch set.
novox/hq ADR 0086. Merge second of four, after mesh-controller (needs `secrets-owner` and the env rule).
- `mesh-controller`: mounts its six own secrets, names them with `_FILE` twins, and owns the files as 65534 — no credential of its own reaches its environment.
- 35 containers in 24 modules carry `secrets-in-environment` with a reason; converting each where its software accepts a path is the per-module work of issue 041.
Proven by the one-node genesis bed on this branch set.
ADR 0086. mesh-controller mounts its six own secrets and names them with
_FILE twins, so no credential of its own reaches its environment. The 35
containers that still read a secret through an env-file carry
secrets-in-environment with the reason; converting each where its software
accepts a path is the per-module work of issue 041.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
novox/hq ADR 0086. Merge second of four, after mesh-controller (needs
secrets-ownerand the env rule).mesh-controller: mounts its six own secrets, names them with_FILEtwins, and owns the files as 65534 — no credential of its own reaches its environment.secrets-in-environmentwith a reason; converting each where its software accepts a path is the per-module work of issue 041.Proven by the one-node genesis bed on this branch set.