Backup lines are derived from each module's data section instead of written by hand; the holder measures declared items, reads the array under them, and deletes a retired item only after a last restore point; the Go providers say each held consumer's size so an empty replacement is seen.
116 lines
2.2 KiB
JSON
116 lines
2.2 KiB
JSON
{
|
|
"module": "mesh-vault",
|
|
"version": "1",
|
|
"provides": [
|
|
{
|
|
"name": "secret",
|
|
"scope": "mesh",
|
|
"identity": {
|
|
"in": "a vault entry"
|
|
}
|
|
}
|
|
],
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"provisioned",
|
|
"rotated",
|
|
"deprovisioned"
|
|
],
|
|
"consumes": [
|
|
"mesh-vault.provisioned",
|
|
"mesh-vault.rotated",
|
|
"mesh-vault.deprovisioned"
|
|
],
|
|
"receives": {
|
|
"secret": "${dir:grants}/mesh.json"
|
|
},
|
|
"grants": {
|
|
"secret": "${dir:grants}"
|
|
},
|
|
"keeps": "/var/lib/mesh-vault/root",
|
|
"data": {
|
|
"own": [
|
|
{
|
|
"id": "state",
|
|
"path": "${dir:state}",
|
|
"class": "valuable",
|
|
"why": "the vault's own keys"
|
|
},
|
|
{
|
|
"id": "ledger",
|
|
"path": "${dir:ledger}",
|
|
"class": "valuable",
|
|
"why": "every secret the vault keeps"
|
|
},
|
|
{
|
|
"id": "root",
|
|
"path": "${dir:root}",
|
|
"class": "valuable",
|
|
"why": "the vault's root material"
|
|
}
|
|
],
|
|
"consumers": {
|
|
"secret": {
|
|
"class": "valuable",
|
|
"in": "ledger",
|
|
"why": "a secret given to a consumer is kept nowhere else in the clear"
|
|
}
|
|
}
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "grants",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "ledger",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "root",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "code",
|
|
"kind": "bundle",
|
|
"language": "typescript",
|
|
"entrypoints": [
|
|
"index.js",
|
|
"tools/index.js",
|
|
"provisioner/index.js"
|
|
],
|
|
"loads": [
|
|
"index.js",
|
|
"tools/index.js",
|
|
"provisioner/index.js"
|
|
],
|
|
"env": {
|
|
"MESH_RECEIVES": "${dir:grants}/mesh.json",
|
|
"MESH_VAULT_LEDGER": "${dir:ledger}",
|
|
"MESH_VAULT_ROOT": "${dir:root}"
|
|
}
|
|
}
|
|
]
|
|
},
|
|
"claims": [
|
|
{
|
|
"name": "mesh-vault",
|
|
"scope": "mesh"
|
|
}
|
|
]
|
|
}
|