lavinmq: the broker TLS directory is the operator's, read by whoever needs it #95

Merged
jschoubben merged 1 commits from fix/the-broker-tls-directory-is-the-operators into main 2026-09-26 14:12:45 +00:00
Owner

The controller now accesses /var/lib/mesh-broker-tls (mesh-controller #54) and the push refused whole: lavinmq declared the directory as an owned resource, and shared data is the operator's, owned by no module (ADR 0051). lavinmq only ever reads the certs — genesis laid them down — so it declares a read access like the controller does, and the directory belongs to nobody. Found landing today's merges: the refusal fired on the first push carrying the new controller.

The controller now accesses `/var/lib/mesh-broker-tls` (mesh-controller #54) and the push refused whole: lavinmq declared the directory as an owned resource, and shared data is the operator's, owned by no module (ADR 0051). lavinmq only ever reads the certs — genesis laid them down — so it declares a read access like the controller does, and the directory belongs to nobody. Found landing today's merges: the refusal fired on the first push carrying the new controller.
jschoubben added 1 commit 2026-09-26 14:12:38 +00:00
The controller now accesses /var/lib/mesh-broker-tls (mesh-controller
#54) and the push refused whole: lavinmq declared the directory as an
owned resource, and shared data is the operator's, owned by no module
(ADR 0051). lavinmq only ever reads the certs — genesis laid them down
— so it declares a read access like the controller does, and the
directory belongs to nobody.
jschoubben merged commit 78595e4db3 into main 2026-09-26 14:12:45 +00:00
jschoubben deleted branch fix/the-broker-tls-directory-is-the-operators 2026-09-26 14:12:46 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#95