Multiple fixes: five modules keep their secrets from the vault (ADR 0094), the authority makes its own root (076), the builder on the host network, route-proxy declares its bases
#34
Merged
jschoubbenmerged 5 commits from multiple-fixes into main2026-09-21 20:58:24 +00:00
ADR 0094 used: gitea, umami, influxdb, icecast and mailu require secret and keep each of theirs under a local name; the broker account stays their own. Parsed by the catalogue-wide test; the whole-mesh beds install the vault first.
076: step-ca's root certificate, key and key password were minted own secrets — random bytes. The mesh mints only its password now; step-ca makes its root at first start and serves it at /roots.pem, named in serves. route-proxy fetches it over the mesh network in a run-once gate before the server starts (ADR 0098). After review: the gate retries with a timeout for two minutes and refuses a body that is not a certificate; its image and the proxy's are declared artifacts (upstream copy per ADR 0096, image per ADR 0097).
The builder runs on the host network: the registry copy (ADR 0096) reaches the mesh's registry over HTTP from inside the builder, where loopback on the bridge was not the machine. Found by the genesis bed, fixed, genesis green.
route-proxy's recipe declares its bases (ADR 0097), and the lab's proxy build starts FROM them.
Proof: genesis-single green (b348627/82256fc); route-forwarding green at ac651c7 (step-ca + route-proxy + hello-web from the catalogue, machine placed on the overlay first). Reviewed by an independent agent; its findings folded in, two follow-ups filed as hq issues 077 and 078. Companion MRs on multiple-fixes: mesh-controller, mesh-tools, mesh-lab, hq.
- **ADR 0094 used:** gitea, umami, influxdb, icecast and mailu require `secret` and keep each of theirs under a local name; the broker account stays their own. Parsed by the catalogue-wide test; the whole-mesh beds install the vault first.
- **076:** step-ca's root certificate, key and key password were minted own secrets — random bytes. The mesh mints only its password now; step-ca makes its root at first start and serves it at `/roots.pem`, named in `serves`. route-proxy fetches it over the mesh network in a run-once gate before the server starts (ADR 0098). After review: the gate retries with a timeout for two minutes and refuses a body that is not a certificate; its image and the proxy's are declared artifacts (upstream copy per ADR 0096, image per ADR 0097).
- **The builder runs on the host network:** the registry copy (ADR 0096) reaches the mesh's registry over HTTP from inside the builder, where loopback on the bridge was not the machine. Found by the genesis bed, fixed, genesis green.
- **route-proxy's recipe declares its bases** (ADR 0097), and the lab's proxy build starts FROM them.
Proof: genesis-single green (b348627/82256fc); route-forwarding green at ac651c7 (step-ca + route-proxy + hello-web from the catalogue, machine placed on the overlay first). Reviewed by an independent agent; its findings folded in, two follow-ups filed as hq issues 077 and 078. Companion MRs on `multiple-fixes`: mesh-controller, mesh-tools, mesh-lab, hq.
gitea, umami, influxdb, icecast and mailu require a secret and keep each of theirs
under a local name (novox/hq ADR 0094); the broker account stays their own. The
route proxy's recipe starts FROM the bases its manifest declares (ADR 0097).
The copy between registries (ADR 0096) reaches the mesh's registry over HTTP from
inside the builder's container, where loopback on the default bridge is not the
machine; docker push never noticed because it went through the machine's daemon.
The builder already holds the runtime's socket, so the host network adds nothing
it did not have.
step-ca's root certificate, its key and that key's password were own secrets — random
bytes the mesh minted, which no certificate is (novox/hq 04-ISSUES/076). The mesh
mints only the CA password now; step-ca makes its root at first start and serves it
at /roots.pem, which the manifest now names beside the ACME directory. The route
proxy fetches that root over the mesh network in a run-once step before it starts,
instead of being handed a served fact that could only be written before anything ran
(ADR 0098).
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
secretand keep each of theirs under a local name; the broker account stays their own. Parsed by the catalogue-wide test; the whole-mesh beds install the vault first./roots.pem, named inserves. route-proxy fetches it over the mesh network in a run-once gate before the server starts (ADR 0098). After review: the gate retries with a timeout for two minutes and refuses a body that is not a certificate; its image and the proxy's are declared artifacts (upstream copy per ADR 0096, image per ADR 0097).Proof: genesis-single green (b348627/82256fc); route-forwarding green at
ac651c7(step-ca + route-proxy + hello-web from the catalogue, machine placed on the overlay first). Reviewed by an independent agent; its findings folded in, two follow-ups filed as hq issues 077 and 078. Companion MRs onmultiple-fixes: mesh-controller, mesh-tools, mesh-lab, hq.