secret accept — carry a value the mesh did not make
The entry point for adopting something already running, and the half that was missing. The store has carried the distinction since the beginning — a module secret records whether it was `made` or `accepted`, and refuses to invent a replacement for the second — and AcceptSecretForModule existed, with exactly one caller: the broker account issued to a build machine. Nothing else could write one. Without it every module secret is generated, which against a database that already exists puts 32 random bytes where a working credential was. The machine applies it, reports success, and whatever reads it fails to authenticate somewhere else entirely, with the mesh insisting the secret was delivered — which it was. The value is read from a file or from standard input, never from an argument: a value on the command line is in the shell's history and in the process list. Same path a model-access key already takes, and no new dependency — the first version reached for x/term and the existing one needed nothing. Sealed on the way in, plaintext discarded, and not printed back. The only difference from a generated secret is where the value came from. Two rules with a test each, and the second is the one that would have been got wrong: only the line ending is removed, never surrounding space. Trimming both ends is the obvious thing and would deliver a password chosen with a leading space as a different password, silently. Both were briefly untested for different reasons — the trimming lived where no test could reach it, and then a -run filter matched neither test. Extracted, and injected against the whole suite.
This commit is contained in:
@@ -94,6 +94,8 @@ func run() error {
|
||||
return assignCommand(ctx, args[0], args[1:])
|
||||
case "settings":
|
||||
return settingsCommand(ctx, args[1:])
|
||||
case "secret":
|
||||
return secretCommand(ctx, args[1:])
|
||||
case "plan":
|
||||
return planCommand(ctx, args[1:])
|
||||
case "push":
|
||||
@@ -138,6 +140,8 @@ func usage() {
|
||||
settings set <module> <file> what a module's config should say, for the whole mesh
|
||||
settings set <module> <file> --node <n> ...or for one machine
|
||||
settings clear <module> [--node <n>] take a layer away
|
||||
secret accept <node> <module> <name> carry a value the mesh did not make and cannot invent
|
||||
secret accept ... --from <file> ...read it from a file rather than being asked
|
||||
build <repository> [--ref R] have a build machine build it, and record what came out
|
||||
build --behind build every module the mesh holds older than its source
|
||||
builds [<module>] what has been built lately, and what came of it
|
||||
|
||||
Reference in New Issue
Block a user