The controller reads its credentials from files; every other env-file secret says why #31

Merged
jschoubben merged 2 commits from feat/secret-not-in-environment into main 2026-09-21 09:59:08 +00:00
Owner

novox/hq ADR 0086. Merge second of four, after mesh-controller (needs secrets-owner and the env rule).

  • mesh-controller: mounts its six own secrets, names them with _FILE twins, and owns the files as 65534 — no credential of its own reaches its environment.
  • 35 containers in 24 modules carry secrets-in-environment with a reason; converting each where its software accepts a path is the per-module work of issue 041.

Proven by the one-node genesis bed on this branch set.

novox/hq ADR 0086. Merge second of four, after mesh-controller (needs `secrets-owner` and the env rule). - `mesh-controller`: mounts its six own secrets, names them with `_FILE` twins, and owns the files as 65534 — no credential of its own reaches its environment. - 35 containers in 24 modules carry `secrets-in-environment` with a reason; converting each where its software accepts a path is the per-module work of issue 041. Proven by the one-node genesis bed on this branch set.
jschoubben added 2 commits 2026-09-21 08:44:07 +00:00
ADR 0086. mesh-controller mounts its six own secrets and names them with
_FILE twins, so no credential of its own reaches its environment. The 35
containers that still read a secret through an env-file carry
secrets-in-environment with the reason; converting each where its software
accepts a path is the per-module work of issue 041.
jschoubben merged commit db597bcb71 into main 2026-09-21 09:59:08 +00:00
jschoubben deleted branch feat/secret-not-in-environment 2026-09-21 09:59:09 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#31