// mesh-vault's events entrypoint, loaded by the per-node tool host (the provisioner runs in the same // process — ADR 0052). The lifecycle events are EMITTED from the provisioner, where custody // actually changes (novox/hq ADR 0041/0042): // module.mesh-vault.secret.provisioned — a consumer was granted a secret // module.mesh-vault.secret.rotated — that consumer's value changed (`rotate secret`) // module.mesh-vault.secret.deprovisioned — the consumer went away and its secret was withdrawn // Here the vault reacts to them, keeping a lightweight audit line of who holds what and when it // moved — the audit an owner of secrets is best placed to log. Fingerprints, never values. import { on } from "@novox/mesh-sdk/events"; interface SecretEvent { as: string; consumer?: string; fingerprint?: string; rotations?: number; } await on("secret.provisioned", async (e) => { console.log(`[mesh-vault] secret provisioned for ${e.body.as} on ${e.body.consumer} (${e.body.fingerprint})`); }); await on("secret.rotated", async (e) => { console.log(`[mesh-vault] secret rotated for ${e.body.as} — rotation ${e.body.rotations} (${e.body.fingerprint})`); }); await on("secret.deprovisioned", async (e) => { console.log(`[mesh-vault] secret withdrawn from ${e.body.as}`); }); console.log("[mesh-vault] auditing secret lifecycle events");