A consumer can write its own connection string

novox/hq 04-ISSUES/023. A consumer was given its password, the address,
the port and where its credential lives, and still could not connect —
the user name was invented by the provisioner and recorded nowhere, and
the rest sat in a JSON binding that a program reading KEY=value cannot
use.

Both halves have the same cause: the mesh knew something and did not say
it.

**Who a consumer is, said once.** The provisioner used to derive
mesh_<node>_<module> and that string existed nowhere else — not in the
control plane, not in the binding, and above all not at the consumer,
which has to present it. Now the mesh derives it once and sends it to
both ends, so they agree by construction rather than by two conventions
that were the same on the day they were written. The provisioners refuse
to invent one if the mesh says nothing, because falling back to a name
of their own would create a role the consumer would never guess and
everything would report success.

**Bound values reach the file that needs them.** ${bound:provision:key}
is the symmetric twin of the sealed placeholder, and simpler: these
values are not secret, so the control plane fills them in before sending
and the host gains no field and learns no format. It stays
name-agnostic — at, as and from are true of any provision, and every
other key comes from what the provider said it serves.

The asymmetry it removes was backwards. The secret is the hard case,
because the mesh must not be able to read it, and the secret was the
part that already arrived.

Keycloak and Gitea now produce complete connections, asserted from the
manifests on disk rather than from fixtures: every part filled, no
placeholder surviving as a value, and the password still a hole only the
host can close. Three faults injected, each caught.
This commit is contained in:
2026-09-01 03:03:07 +02:00
parent 96f90ab986
commit 122680b554
10 changed files with 550 additions and 19 deletions
@@ -5,6 +5,8 @@ import (
"path/filepath"
"strings"
"testing"
"github.com/novox/mesh-control/internal/catalogue"
)
// The password comes from a file, because that is how the mesh delivers one.
@@ -83,3 +85,25 @@ func TestARoleNameTooLongToBeDistinctIsRefused(t *testing.T) {
t.Errorf("the refusal does not say what goes wrong: %v", err)
}
}
// The prefix this provisioner removes by is the prefix the mesh names by.
//
// **Two definitions on purpose.** A provisioner is a separate program and anyone may write one, so
// the prefix is part of the contract rather than a symbol to import — the same reason the grant
// file's shape is written down rather than shared. But a contract with two copies and no check is
// a contract until somebody edits one: if the mesh named `nox_` and this removed `mesh_`, every
// login it created would be permanent, and nothing would report anything at all.
func TestTheMarkAgreesWithWhatTheMeshNamesBy(t *testing.T) {
if mark != catalogue.IdentityPrefix {
t.Fatalf(
"this provisioner removes what begins with %q and the mesh names things %q, so it "+
"would never remove anything it made", mark, catalogue.IdentityPrefix)
}
}
// And a name the mesh would produce is one this provisioner accepts.
func TestWhatTheMeshNamesIsUsableAsARole(t *testing.T) {
if err := usableRole(catalogue.ConsumerIdentity("home-server", "keycloak")); err != nil {
t.Fatalf("the mesh named a consumer and this cannot make a role for it: %v", err)
}
}