A pair credential is sealed to the operator key too

The secret the vault provides a module is the credential of the consumer↔vault
pair, and so is every credential a provider grants; sealing only own secrets
to the operator left exactly those unrecoverable. Same column, same call; the
export and `secret recover` address a pair by consumer node, module and the
provision's name, and say which kind each entry is.
This commit is contained in:
2026-09-21 00:36:16 +02:00
parent e140ed5d0b
commit 565f144a20
5 changed files with 131 additions and 11 deletions
+9
View File
@@ -739,10 +739,19 @@ func receivedFile(requirement, path string, given []Contribution) (map[string]an
// Kept is one secret as the operator can recover it: where it belongs, and the value sealed to the
// operator's key. Never a node's blob, and never a value.
//
// Two kinds, addressed the same way — by the node and module that hold it and the name they know
// it by. An `own` secret is one a module has for itself; a `pair` secret is a credential the
// module was granted for a provision it requires (`name` is the provision), and Provider says which
// node grants it.
type Kept struct {
Node string `json:"node"`
Module string `json:"module"`
Name string `json:"name"`
// Kind is `own` or `pair`.
Kind string `json:"kind"`
// Provider is the node granting a pair credential; empty for an own secret.
Provider string `json:"provider,omitempty"`
// Origin is `made` or `accepted` — whether the mesh minted it or a person supplied it.
Origin string `json:"origin"`
// Sealed is the value, sealed to the operator key named in Key.