An operator delivers a pair credential, and the mesh never replaces it

secret accept grows --provider: the value is sealed to the consumer's node, the
provider's node and the operator's key, and the pair records origin 'accepted'.
An accepted pair is not remade when a key changes (the mesh does not hold the
value; the read is refused naming the remedy) and rotate refuses it (accepting a
new value is the rotation). The vault's third species has its entry
(novox/hq 04-ISSUES/070, ADR 0092).
This commit is contained in:
2026-09-21 17:50:41 +02:00
parent 537ad544d3
commit 396e05bb65
4 changed files with 188 additions and 4 deletions
@@ -0,0 +1,14 @@
-- A pair credential records whether the mesh made it or a person supplied it
-- (novox/hq 04-ISSUES/070, ADR 0092).
--
-- Every pair credential so far was made: generated, sealed to both ends, the plaintext discarded,
-- remade whenever either end's key changed and replaced whole by `rotate`. A module's own secret
-- has carried `origin` since the beginning so an accepted one is never replaced by a minted one;
-- a pair could not be accepted at all, so the vault's third species -- a credential for something
-- outside the mesh, which only a person can supply -- had no entry.
--
-- An accepted pair is not remade when a key changes (the mesh cannot: it does not hold the
-- value) and is not rotated (there is nothing to rotate to); both are refused aloud, and the
-- remedy is to accept it again.
alter table secret add column origin text not null default 'made';