From 89e0dde9e080f387d8b9d9c1192afa597d565b27 Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 1 Oct 2026 17:19:05 +0200 Subject: [PATCH 1/2] The vault's claim and its own event names return The uplink branch was split from the vault's with the vault's files reset to a main that did not yet hold #205; merging it afterwards took the older vault definition along (no claim, the refused event names), and the vault could not be built. Restored to #205's state. --- modules/mesh-vault/index.ts | 12 ++++++------ modules/mesh-vault/module.json | 20 +++++++++++++------- modules/mesh-vault/provisioner/index.ts | 2 +- 3 files changed, 20 insertions(+), 14 deletions(-) diff --git a/modules/mesh-vault/index.ts b/modules/mesh-vault/index.ts index 540a780..80f74f3 100644 --- a/modules/mesh-vault/index.ts +++ b/modules/mesh-vault/index.ts @@ -1,9 +1,9 @@ // mesh-vault's events entrypoint, loaded by the per-node tool host (the provisioner runs in the same // process — ADR 0052). The lifecycle events are EMITTED from the provisioner, where custody // actually changes (novox/hq ADR 0041/0042): -// module.mesh-vault.secret.provisioned — a consumer was granted a secret -// module.mesh-vault.secret.rotated — that consumer's value changed (`rotate secret`) -// module.mesh-vault.secret.deprovisioned — the consumer went away and its secret was withdrawn +// mesh-vault.provisioned — a consumer was granted a secret +// mesh-vault.rotated — that consumer's value changed (`rotate secret`) +// mesh-vault.deprovisioned — the consumer went away and its secret was withdrawn // Here the vault reacts to them, keeping a lightweight audit line of who holds what and when it // moved — the audit an owner of secrets is best placed to log. Fingerprints, never values. @@ -16,15 +16,15 @@ interface SecretEvent { rotations?: number; } -await on("secret.provisioned", async (e) => { +await on("provisioned", async (e) => { console.log(`[mesh-vault] secret provisioned for ${e.body.as} on ${e.body.consumer} (${e.body.fingerprint})`); }); -await on("secret.rotated", async (e) => { +await on("rotated", async (e) => { console.log(`[mesh-vault] secret rotated for ${e.body.as} — rotation ${e.body.rotations} (${e.body.fingerprint})`); }); -await on("secret.deprovisioned", async (e) => { +await on("deprovisioned", async (e) => { console.log(`[mesh-vault] secret withdrawn from ${e.body.as}`); }); diff --git a/modules/mesh-vault/module.json b/modules/mesh-vault/module.json index 991e237..29e17a3 100644 --- a/modules/mesh-vault/module.json +++ b/modules/mesh-vault/module.json @@ -11,14 +11,14 @@ "container-runtime" ], "emits": [ - "secret.provisioned", - "secret.rotated", - "secret.deprovisioned" + "provisioned", + "rotated", + "deprovisioned" ], "consumes": [ - "mesh-vault.secret.provisioned", - "mesh-vault.secret.rotated", - "mesh-vault.secret.deprovisioned" + "mesh-vault.provisioned", + "mesh-vault.rotated", + "mesh-vault.deprovisioned" ], "receives": { "secret": "${dir:grants}/mesh.json" @@ -98,5 +98,11 @@ "from": "Dockerfile" } ] - } + }, + "claims": [ + { + "name": "mesh-vault", + "scope": "mesh" + } + ] } diff --git a/modules/mesh-vault/provisioner/index.ts b/modules/mesh-vault/provisioner/index.ts index ad0872c..37808a1 100644 --- a/modules/mesh-vault/provisioner/index.ts +++ b/modules/mesh-vault/provisioner/index.ts @@ -43,6 +43,6 @@ runProvisioner("secret", { async remove(p: { as: string }): Promise { if (!ledger.withdraw(p.as)) return; console.log(`[mesh-vault] withdrawn: ${p.as}`); - await announce("secret.deprovisioned", { as: p.as }); + await announce("deprovisioned", { as: p.as }); }, }); -- 2.54.0 From 01d68bda880efb1cb4544106f5e7a897a8ca7afc Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 1 Oct 2026 17:19:41 +0200 Subject: [PATCH 2/2] And the uplink holders' capabilities return The same split lost them the other way round: the merge base held both changes, each branch had reset the other's files, and the three-way merge kept neither. Both halves of hq ADR 0161 are on main again with this. --- modules/dhcpcd/module.json | 3 ++- modules/networkmanager/module.json | 3 ++- modules/systemd-networkd/module.json | 3 ++- 3 files changed, 6 insertions(+), 3 deletions(-) diff --git a/modules/dhcpcd/module.json b/modules/dhcpcd/module.json index 89ffe07..23c658e 100644 --- a/modules/dhcpcd/module.json +++ b/modules/dhcpcd/module.json @@ -3,7 +3,8 @@ "version": "1", "capabilities": [ "package-manager", - "service-manager" + "service-manager", + "uplink-dhcpcd" ], "claims": [ { diff --git a/modules/networkmanager/module.json b/modules/networkmanager/module.json index 5aaa8f6..37c2ba7 100644 --- a/modules/networkmanager/module.json +++ b/modules/networkmanager/module.json @@ -3,7 +3,8 @@ "version": "1", "capabilities": [ "package-manager", - "service-manager" + "service-manager", + "uplink-networkmanager" ], "claims": [ { diff --git a/modules/systemd-networkd/module.json b/modules/systemd-networkd/module.json index 040b67e..370cf1d 100644 --- a/modules/systemd-networkd/module.json +++ b/modules/systemd-networkd/module.json @@ -3,7 +3,8 @@ "version": "1", "capabilities": [ "package-manager", - "service-manager" + "service-manager", + "uplink-systemd-networkd" ], "claims": [ { -- 2.54.0