Several secrets expand where the consumer is known, not on the first module to mention the provision

The lab's two-secrets consumer was given one credential and no file: the expansion
ran on the resolver's walk over names, on whichever module mentioned the provision
first, and the per-consumer pass copied that. It expands in that pass now, and a
test has two consumers of one provision, one keeping one file and one keeping two.
This commit is contained in:
2026-09-21 20:36:19 +02:00
parent 973cda5d76
commit 76773dfbf5
2 changed files with 20 additions and 7 deletions
+6 -4
View File
@@ -302,7 +302,7 @@ func Resolve(catalogue map[string]Manifest, assigned []string, node Node, world
if at == "" {
at = "127.0.0.1"
}
needs = eachLocal(needs, catalogue, Needed{
needs = append(needs, Needed{
Name: want, From: node.Name, At: at,
Serves: servedHere(catalogue, chosen, want), For: because[want]})
} else if served := servedHere(catalogue, chosen, want); len(served) > 0 {
@@ -323,7 +323,7 @@ func Resolve(catalogue map[string]Manifest, assigned []string, node Node, world
if at == "" {
at = "127.0.0.1"
}
needs = eachLocal(needs, catalogue, Needed{
needs = append(needs, Needed{
Name: want, From: node.Name, At: at, Serves: served, For: because[want]})
}
continue
@@ -351,7 +351,7 @@ func Resolve(catalogue map[string]Manifest, assigned []string, node Node, world
node.Name, want, p.Node, meshNetwork))
return
}
needs = eachLocal(needs, catalogue, Needed{Name: want, From: p.Node, At: p.At,
needs = append(needs, Needed{Name: want, From: p.Node, At: p.At,
Serves: p.Serves, For: because[want]})
}
switch {
@@ -847,7 +847,9 @@ func perConsumer(needs []Needed, order []string, catalogue map[string]Manifest)
}
copied := n
copied.For = m.Module
out = append(out, copied)
// And once per file THIS module keeps the credential in, where it keeps several
// (ADR 0094) — here, where the consumer is finally known, not on the walk above.
out = eachLocal(out, catalogue, copied)
wanted = true
break
}