A pair credential is sealed to the operator key too
The secret the vault provides a module is the credential of the consumer↔vault pair, and so is every credential a provider grants; sealing only own secrets to the operator left exactly those unrecoverable. Same column, same call; the export and `secret recover` address a pair by consumer node, module and the provision's name, and say which kind each entry is.
This commit is contained in:
@@ -74,20 +74,35 @@ func (i *Inventory) SecretFor(ctx context.Context, name, consumer, consumerModul
|
||||
return held, nil
|
||||
}
|
||||
|
||||
made, err := secrets.Make(consumerKey, providerKey)
|
||||
// And to the operator, when the mesh has one (novox/hq ADR 0085, amended): the third copy that
|
||||
// makes a vault-provided secret recoverable, and nothing the mesh can open.
|
||||
operator, err := i.OperatorKey(ctx)
|
||||
if err != nil {
|
||||
return Secret{}, err
|
||||
}
|
||||
var also []string
|
||||
if operator != "" {
|
||||
also = append(also, operator)
|
||||
}
|
||||
made, more, err := secrets.MakeAlso(consumerKey, providerKey, also...)
|
||||
if err != nil {
|
||||
return Secret{}, err
|
||||
}
|
||||
var forOperator, operatorKey *string
|
||||
if operator != "" {
|
||||
forOperator, operatorKey = &more[0], &operator
|
||||
}
|
||||
_, err = i.store.Pool().Exec(ctx,
|
||||
`insert into secret (name, consumer, consumer_module, provider, for_consumer, for_provider,
|
||||
consumer_key, provider_key)
|
||||
values ($1, $2, $3, $4, $5, $6, $7, $8)
|
||||
consumer_key, provider_key, operator_sealed, operator_key)
|
||||
values ($1, $2, $3, $4, $5, $6, $7, $8, $9, $10)
|
||||
on conflict (name, consumer, consumer_module, provider) do update set
|
||||
for_consumer = excluded.for_consumer, for_provider = excluded.for_provider,
|
||||
consumer_key = excluded.consumer_key, provider_key = excluded.provider_key,
|
||||
created_at = now()`,
|
||||
created_at = now(),
|
||||
operator_sealed = excluded.operator_sealed, operator_key = excluded.operator_key`,
|
||||
name, consumerNode.ID, consumerModule, providerNode.ID,
|
||||
made.ForConsumer, made.ForProvider, made.ConsumerKey, made.ProviderKey)
|
||||
made.ForConsumer, made.ForProvider, made.ConsumerKey, made.ProviderKey, forOperator, operatorKey)
|
||||
if err != nil {
|
||||
return Secret{}, err
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user