A module may hold several secrets from one provider, each a pair of its own

secrets: maps a requirement to several files under local names. Each local name is
its own need, its own pair credential (the pair is keyed on it: migration 0027),
its own file on the consumer, its own holder at the provider (the identity with the
local name after it) and rotates apart from the others. The plain shape is
unchanged and every existing row is the credential it was (novox/hq 04-ISSUES/069,
ADR 0094).
This commit is contained in:
2026-09-21 20:28:16 +02:00
parent f3bfc11565
commit 6ae4ae1dba
13 changed files with 567 additions and 142 deletions
+2 -2
View File
@@ -164,7 +164,7 @@ func TestAPairCredentialIsSealedToTheOperatorToo(t *testing.T) {
if _, err := inv.SetOperatorKey(ctx, pub); err != nil {
t.Fatal(err)
}
made, err := inv.SecretFor(ctx, "secret", "consumer", "gitea", "provider")
made, err := inv.SecretFor(ctx, "secret", "consumer", "gitea", "provider", "")
if err != nil {
t.Fatal(err)
}
@@ -191,7 +191,7 @@ func TestAPairCredentialIsSealedToTheOperatorToo(t *testing.T) {
// A second provider of the same provision: two rows, refused rather than the first one taken,
// unless the provider is named. And replacing the key counts pair credentials as orphaned.
if _, err := inv.SecretFor(ctx, "secret", "consumer", "gitea", "consumer"); err != nil {
if _, err := inv.SecretFor(ctx, "secret", "consumer", "gitea", "consumer", ""); err != nil {
t.Fatal(err)
}
if _, err := inv.KeptSecret(ctx, "consumer", "gitea", "secret", ""); err == nil || !strings.Contains(err.Error(), "--provider") {