novox/hq ADR 0085 (amended), design 24. Merge second of five, after mesh-controller (needs its keeps field and secret provision handling).
modules/mesh-vault: provides secret; a ledger of who holds one and its fingerprint, tools secret_holders / secret_verify / secret_export that never return a value; keeps the operator-sealed export at /var/lib/mesh-vault/root.
redis: its own password becomes a secret it requires from the vault; the server restarts on its config so rotation reaches it.
postgres: the store reads its superuser from /var/lib/postgres/superuser.secret (genesis writes it, the mesh keeps it); lavinmq: the admin password is an own secret read from a file, not a literal in the runtime's env.
Proven by mesh-lab assigned-vault.test.ts and one-node-mesh.test.ts on this branch set.
novox/hq ADR 0085 (amended), design 24. Merge second of five, after mesh-controller (needs its `keeps` field and `secret` provision handling).
- `modules/mesh-vault`: provides `secret`; a ledger of who holds one and its fingerprint, tools `secret_holders` / `secret_verify` / `secret_export` that never return a value; keeps the operator-sealed export at `/var/lib/mesh-vault/root`.
- redis: its own password becomes a `secret` it requires from the vault; the server restarts on its config so rotation reaches it.
- postgres: the store reads its superuser from `/var/lib/postgres/superuser.secret` (genesis writes it, the mesh keeps it); lavinmq: the admin password is an own secret read from a file, not a literal in the runtime's env.
Proven by mesh-lab `assigned-vault.test.ts` and `one-node-mesh.test.ts` on this branch set.
mesh-vault provides `secret` (novox/hq ADR 0085, design 24). The value is
the pair credential the controller mints — the vault holds no copy, only a
ledger of who holds one, its fingerprint and every rotation, and two tools that
answer by fingerprint and never by value. Rotation is `rotate secret`,
unchanged machinery pointed at a secret with an owner (design 13). Named in the
mesh's own namespace, beside mesh-controller and mesh-catalog, because it is
the mesh's own code rather than wrapped software.
redis is the first consumer: its own password stops being an own-secret nothing
could rotate and becomes a `secret` it requires, read from the same file into
the same hole. The server now restarts on its config, or it would keep the
password it started with through every rotation (playbook 06).
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
novox/hq ADR 0085 (amended), design 24. Merge second of five, after mesh-controller (needs its
keepsfield andsecretprovision handling).modules/mesh-vault: providessecret; a ledger of who holds one and its fingerprint, toolssecret_holders/secret_verify/secret_exportthat never return a value; keeps the operator-sealed export at/var/lib/mesh-vault/root.secretit requires from the vault; the server restarts on its config so rotation reaches it./var/lib/postgres/superuser.secret(genesis writes it, the mesh keeps it); lavinmq: the admin password is an own secret read from a file, not a literal in the runtime's env.Proven by mesh-lab
assigned-vault.test.tsandone-node-mesh.test.tson this branch set.