A pair credential is sealed to the operator key too

The secret the vault provides a module is the credential of the consumer↔vault
pair, and so is every credential a provider grants; sealing only own secrets
to the operator left exactly those unrecoverable. Same column, same call; the
export and `secret recover` address a pair by consumer node, module and the
provision's name, and say which kind each entry is.
This commit is contained in:
2026-09-21 00:36:16 +02:00
parent e140ed5d0b
commit 565f144a20
5 changed files with 131 additions and 11 deletions
@@ -0,0 +1,10 @@
-- The same second seal for a pair credential (novox/hq ADR 0085, amended).
--
-- 0023 gave a module's own secrets an operator-sealed copy. A secret the vault provides to a module
-- is not an own secret -- it is the credential of the consumer-vault pair -- and so were the
-- credentials every provider grants. Without this, a vault-provided password could be rotated and
-- audited but not recovered, which is a vault that keeps everything except what it was for.
alter table secret
add column operator_sealed text,
add column operator_key text;