The token carries the node's name

Found by raising a mesh end to end. The broker account a joining node
authenticates as is named after the node, and exists before that machine
has been told anything — so the node has to know its name before the mesh
can tell it. Without it, enrolment fails at the broker with an empty
username, which says nothing about why.

Not a secret, and the issuer already knows it. The wire-format test now
covers it, so a rename on either side fails in both repositories rather
than at enrolment on a real machine.
This commit is contained in:
2026-08-30 02:36:57 +02:00
parent b9aac2b700
commit 02d1020bce
3 changed files with 38 additions and 8 deletions
+1 -1
View File
@@ -352,7 +352,7 @@ func tokenCommand(ctx context.Context, args []string) error {
return err
}
made := token.Token{Signer: key.Public, Secret: issued.Secret}
made := token.Token{Node: issued.Node.Name, Signer: key.Public, Secret: issued.Secret}
// Absent is a state, not a failure: a control plane can hold records and a key before it has
// a broker. What it cannot do is issue a token anybody could use, and Missing() says so.