Recoverable means sealed to the current operator key; recovery names the provider
From review: the export counted any operator-sealed row as recoverable, so a secret sealed to a replaced key was reported as openable with the current one; replacing the key counted orphans in one table of two; and a pair credential held from two providers was recovered as whichever row came first. The export now lists what the current key opens, what an earlier key opens, and what has no copy; `secret recover` takes --provider and refuses ambiguity; files that must not exist are created exclusively; one constructor builds the export for the operator's file and the vault's disk alike.
This commit is contained in:
@@ -13,7 +13,6 @@ import (
|
||||
"github.com/novox/mesh-controller/internal/catalogue"
|
||||
"github.com/novox/mesh-controller/internal/inventory"
|
||||
"github.com/novox/mesh-controller/internal/licences"
|
||||
"github.com/novox/mesh-controller/internal/secrets"
|
||||
"net"
|
||||
"strconv"
|
||||
)
|
||||
@@ -464,27 +463,18 @@ func declarationWith(ctx context.Context, open *stores, node string,
|
||||
}
|
||||
|
||||
// And, for a module that keeps them, every operator-sealed secret in the mesh — the vault's
|
||||
// copy, outside the store (novox/hq ADR 0085, amended). Read only; nothing here mints.
|
||||
// copy, outside the store (novox/hq ADR 0085, amended). Read only; nothing here mints. The
|
||||
// export changes whenever any secret in the mesh is made or rotated, so the vault's declaration
|
||||
// changes with it and the vault node is sent again: that is what keeps its copy current, and
|
||||
// the cost is one two-table read per composition of the vault's node, in every mode.
|
||||
var kept *catalogue.KeptExport
|
||||
for _, m := range plan.Modules {
|
||||
if m.Keeps == "" {
|
||||
continue
|
||||
}
|
||||
operator, err := inv.OperatorKey(ctx)
|
||||
if err != nil {
|
||||
if kept, err = inv.OperatorExport(ctx); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if operator == "" {
|
||||
break // nothing is sealed to an operator, so there is nothing to keep yet
|
||||
}
|
||||
recoverable, unrecoverable, err := inv.KeptForOperator(ctx)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
kept = &catalogue.KeptExport{
|
||||
Export: 1, OperatorKey: operator, Fingerprint: secrets.Fingerprint(operator),
|
||||
Kept: recoverable, Unrecoverable: unrecoverable,
|
||||
}
|
||||
break
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user