The uplink branch was split from the vault's with the vault's files reset to a main that did not yet hold #205; merging it afterwards took the older vault definition along (no claim, the refused event names), and the vault could not be built. Restored to #205's state.
32 lines
1.3 KiB
TypeScript
32 lines
1.3 KiB
TypeScript
// mesh-vault's events entrypoint, loaded by the per-node tool host (the provisioner runs in the same
|
|
// process — ADR 0052). The lifecycle events are EMITTED from the provisioner, where custody
|
|
// actually changes (novox/hq ADR 0041/0042):
|
|
// mesh-vault.provisioned — a consumer was granted a secret
|
|
// mesh-vault.rotated — that consumer's value changed (`rotate secret`)
|
|
// mesh-vault.deprovisioned — the consumer went away and its secret was withdrawn
|
|
// Here the vault reacts to them, keeping a lightweight audit line of who holds what and when it
|
|
// moved — the audit an owner of secrets is best placed to log. Fingerprints, never values.
|
|
|
|
import { on } from "@novox/mesh-sdk/events";
|
|
|
|
interface SecretEvent {
|
|
as: string;
|
|
consumer?: string;
|
|
fingerprint?: string;
|
|
rotations?: number;
|
|
}
|
|
|
|
await on<SecretEvent>("provisioned", async (e) => {
|
|
console.log(`[mesh-vault] secret provisioned for ${e.body.as} on ${e.body.consumer} (${e.body.fingerprint})`);
|
|
});
|
|
|
|
await on<SecretEvent>("rotated", async (e) => {
|
|
console.log(`[mesh-vault] secret rotated for ${e.body.as} — rotation ${e.body.rotations} (${e.body.fingerprint})`);
|
|
});
|
|
|
|
await on<SecretEvent>("deprovisioned", async (e) => {
|
|
console.log(`[mesh-vault] secret withdrawn from ${e.body.as}`);
|
|
});
|
|
|
|
console.log("[mesh-vault] auditing secret lifecycle events");
|