catalogue: a module may name the machine it was assigned to

An authority inside the mesh is reached at <machine>.internal, so its own
certificate must be issued for that name — and it is the one module that cannot
be told its name by a binding, because it provides rather than requires. Written
as a literal it would be one deployment's machine name in a manifest, which is
what ADR 0056 exists to remove.

${machine:name} and ${machine:at}, beside the bound values and refused the same
way. An address the machine does not have is named here rather than discovered
later as a certificate nobody can verify.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-10 21:12:04 +02:00
parent 9fab0b731a
commit 946fddd622
3 changed files with 175 additions and 0 deletions
+9
View File
@@ -421,6 +421,8 @@ func (r Resolution) Declaration(with Rendering) ([]map[string]any, error) {
}
// And what its bindings say, for the half of a connection that is not secret.
known := knownFor(m, r.Needs, r.Node)
// And the machine underneath, which no binding of its own can tell it.
thisMachine := machineFacts(r)
for _, unsettled := range resources {
resource, err := ApplySettings(unsettled, with.Settings[m.Module])
@@ -444,6 +446,13 @@ func (r Resolution) Declaration(with Rendering) ([]map[string]any, error) {
if err := boundInto(copied, known, m.Module); err != nil {
return nil, err
}
// And what the module could not have written: the machine it turned out to be
// assigned to. Beside the bound values because it is the same kind of fact — the
// mesh's own, held in the clear — and because a module that must name itself to
// something else has no binding to learn it from (novox/hq ADR 0056).
if err := machineInto(copied, thisMachine, m.Module); err != nil {
return nil, err
}
if err := pinned(copied, m.Module); err != nil {
return nil, err
}