From 4d62e6caf131f77422814e36a8ad77e03362aed5 Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 28 Sep 2026 01:08:11 +0200 Subject: [PATCH] The mint leaves the control plane's old-bus secret alone The control plane is a module too, and its broker secret is the old bus's credential it is still using while the mint runs. Writing the new bus's blob there cut the mesh off from its own old bus mid-move. Its new-bus credential is the controller principal's bus secret; the module principal is skipped. --- cmd/mesh-controller/rollout.go | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/cmd/mesh-controller/rollout.go b/cmd/mesh-controller/rollout.go index 562a9f7..2ff5600 100644 --- a/cmd/mesh-controller/rollout.go +++ b/cmd/mesh-controller/rollout.go @@ -340,6 +340,14 @@ func rolloutMint(ctx context.Context, again bool) error { machines++ case broker.KindModule: + if p.Module == "mesh-controller" { + // The control plane is a module too, and its `broker` secret is the old bus's + // credential it is still using while this runs. Writing the new bus's blob there + // cut the mesh off from its own old bus mid-move (2026-09-28). Its new-bus credential + // is the controller principal's `bus` secret above; nothing else is needed here. + skipped++ + continue + } m, inShelf := shelf[p.Module] if !inShelf { skipped++