A consumer can write its own connection string

novox/hq 04-ISSUES/023. A consumer was given its password, the address,
the port and where its credential lives, and still could not connect —
the user name was invented by the provisioner and recorded nowhere, and
the rest sat in a JSON binding that a program reading KEY=value cannot
use.

Both halves have the same cause: the mesh knew something and did not say
it.

**Who a consumer is, said once.** The provisioner used to derive
mesh_<node>_<module> and that string existed nowhere else — not in the
control plane, not in the binding, and above all not at the consumer,
which has to present it. Now the mesh derives it once and sends it to
both ends, so they agree by construction rather than by two conventions
that were the same on the day they were written. The provisioners refuse
to invent one if the mesh says nothing, because falling back to a name
of their own would create a role the consumer would never guess and
everything would report success.

**Bound values reach the file that needs them.** ${bound:provision:key}
is the symmetric twin of the sealed placeholder, and simpler: these
values are not secret, so the control plane fills them in before sending
and the host gains no field and learns no format. It stays
name-agnostic — at, as and from are true of any provision, and every
other key comes from what the provider said it serves.

The asymmetry it removes was backwards. The secret is the hard case,
because the mesh must not be able to read it, and the secret was the
part that already arrived.

Keycloak and Gitea now produce complete connections, asserted from the
manifests on disk rather than from fixtures: every part filled, no
placeholder surviving as a value, and the password still a hole only the
host can close. Three faults injected, each caught.
This commit is contained in:
2026-09-01 03:03:07 +02:00
parent 96f90ab986
commit 122680b554
10 changed files with 550 additions and 19 deletions
+21 -4
View File
@@ -50,9 +50,13 @@ const alias = "store"
// contribution is one consumer, as the mesh described it.
type contribution struct {
From string `json:"from"`
// Node is empty for a module on this machine, which is asking for something local and is not
// this provisioner's business.
Node string `json:"node"`
Node string `json:"node"`
// As is what to call the login this consumer will use.
//
// **Given, not invented** (novox/hq 04-ISSUES/023). This provisioner used to make the name
// itself, which worked and meant the consumer — the one thing that has to present it — could
// not learn it. The mesh derives it once and sends it to both ends.
As string `json:"as"`
Secret string `json:"secret"`
Values map[string]any `json:"values"`
}
@@ -195,7 +199,20 @@ func run(ctx context.Context) error {
// One access key per consumer, and a consumer is a module on a machine (novox/hq
// 04-ISSUES/022) — otherwise every service on a node shares one key, and the policy that
// confines each to its own bucket confines none of them.
key := mark + c.Node + "_" + c.From
//
// The name comes from the mesh (04-ISSUES/023), so the consumer knows what it will be.
key := c.As
if key == "" {
return fmt.Errorf(
"%s on %s was granted a bucket and the mesh did not say what to call its key, "+
"so there is no name both ends would agree on", c.From, c.Node)
}
if !strings.HasPrefix(key, mark) {
return fmt.Errorf(
"%s on %s is to be called %q, which does not begin with %q — this provisioner "+
"removes what it made by that prefix, so it would never let this one go",
c.From, c.Node, key, mark)
}
wanted[key] = true
if err := ensureBucket(ctx, bucket); err != nil {
return err