A provider keeps one grant file per holder, with the local name in its id and path

The lab's vault refused a declaration naming two files with one identity: the
two secrets of one consumer. The holder's suffix is in the resource id and the path now.
This commit is contained in:
2026-09-21 20:41:19 +02:00
parent 3e5c010c5e
commit 5049d201c6
3 changed files with 46 additions and 6 deletions
@@ -134,3 +134,28 @@ func TestAProviderSeesEachLocalNameAsAHolderOfItsOwn(t *testing.T) {
t.Fatalf("two holders share one file on the provider: %q", given[0].Secret)
}
}
// And on the provider's machine, two files with two ids — the lab's first run had the declaration
// refused for two resources with one identity.
func TestAProviderKeepsOneFilePerHolder(t *testing.T) {
got, err := Resolve(vaultAndCA(), []string{"mesh-vault", "cache", "ca"}, workstation(), World{})
if err != nil {
t.Fatal(err)
}
out, err := got.Declaration(Rendering{Grants: []Grant{
{Provision: "secret", Consumer: "workstation", From: "ca", Local: "root-key", Sealed: "x"},
{Provision: "secret", Consumer: "workstation", From: "ca", Local: "root-pass", Sealed: "y"},
}})
if err != nil {
t.Fatal(err)
}
ids := map[string]string{}
for _, r := range out {
if id, _ := r["id"].(string); strings.Contains(id, "grant-secret") {
ids[id] = r["path"].(string)
}
}
if len(ids) != 2 {
t.Fatalf("two holders are two grant files: %v", ids)
}
}