A consumer can write its own connection string

novox/hq 04-ISSUES/023. A consumer was given its password, the address,
the port and where its credential lives, and still could not connect —
the user name was invented by the provisioner and recorded nowhere, and
the rest sat in a JSON binding that a program reading KEY=value cannot
use.

Both halves have the same cause: the mesh knew something and did not say
it.

**Who a consumer is, said once.** The provisioner used to derive
mesh_<node>_<module> and that string existed nowhere else — not in the
control plane, not in the binding, and above all not at the consumer,
which has to present it. Now the mesh derives it once and sends it to
both ends, so they agree by construction rather than by two conventions
that were the same on the day they were written. The provisioners refuse
to invent one if the mesh says nothing, because falling back to a name
of their own would create a role the consumer would never guess and
everything would report success.

**Bound values reach the file that needs them.** ${bound:provision:key}
is the symmetric twin of the sealed placeholder, and simpler: these
values are not secret, so the control plane fills them in before sending
and the host gains no field and learns no format. It stays
name-agnostic — at, as and from are true of any provision, and every
other key comes from what the provider said it serves.

The asymmetry it removes was backwards. The secret is the hard case,
because the mesh must not be able to read it, and the secret was the
part that already arrived.

Keycloak and Gitea now produce complete connections, asserted from the
manifests on disk rather than from fixtures: every part filled, no
placeholder surviving as a value, and the password still a hole only the
host can close. Three faults injected, each caught.
This commit is contained in:
2026-09-01 03:03:07 +02:00
parent 96f90ab986
commit 122680b554
10 changed files with 550 additions and 19 deletions
+60
View File
@@ -359,3 +359,63 @@ func secretsUsedForTest(content string) []string {
}
return used
}
// The real manifests, resolved together, produce a connection a program could use.
//
// **Parsing is not working, and this file has now learned that twice.** These modules parsed and
// resolved for a day while their credentials went into files nothing could read; they would have
// parsed and resolved just as happily with a connection string that named no user. What has to be
// true is that the bytes reaching the machine are usable, so that is what this asks.
func TestKeycloakGetsAConnectionAProgramCouldUse(t *testing.T) {
shelf := map[string]catalogue.Manifest{}
for _, name := range []string{"postgres.json", "keycloak.json"} {
m := read(t, name)
shelf[m.Module] = m
}
resolved, err := catalogue.Resolve(shelf, []string{"keycloak"},
catalogue.Node{Name: "workstation", At: "workstation.internal",
Capabilities: map[string]bool{"container-runtime": true}},
catalogue.World{Offered: map[string][]catalogue.Provider{
"postgres-database": {{Node: "anchor", At: "anchor.internal",
Serves: map[string]any{"port": float64(5432)}}},
}})
if err != nil {
t.Fatalf("the real manifests do not resolve: %v", err)
}
for i := range resolved.Needs {
resolved.Needs[i].Sealed = "sealed"
}
out, err := resolved.Declaration(catalogue.Rendering{
Needed: map[string]map[string]string{"keycloak": {"admin": "sealed-admin"}},
})
if err != nil {
t.Fatalf("the real manifests do not declare: %v", err)
}
var env string
for _, r := range out {
if r["path"] == "/var/lib/keycloak/database.env" {
env, _ = r["content"].(string)
}
}
if env == "" {
t.Fatal("keycloak was given no database configuration at all")
}
// Every part of a connection, and nothing left unfilled. A leftover ${...} would be read as
// a value by whatever parses this.
for _, wanted := range []string{
"KC_DB_URL=jdbc:postgresql://anchor.internal:5432/keycloak",
"KC_DB_USERNAME=mesh_workstation_keycloak",
} {
if !strings.Contains(env, wanted) {
t.Errorf("the connection is missing %q:\n%s", wanted, env)
}
}
if strings.Contains(env, "${bound:") {
t.Errorf("a placeholder reached the machine as a value:\n%s", env)
}
// The password is the one hole that stays, because only the host may fill it.
if !strings.Contains(env, "KC_DB_PASSWORD=${secret:postgres-database}") {
t.Errorf("the password is not left for the host to fill:\n%s", env)
}
}