identity: a consumer's identity fits the tightest backend, via a slug (ADR 0054)

A module may declare a short `slug`; the mesh derives mesh_<node>_<slug|name> and
refuses at assignment (naming the slug as the remedy) when it would still overflow —
identityLimit is now 20, an S3 access key's, the tightest of the backends a login
reaches (04-ISSUES/010). The slug rides the grant so the provider derives the same
login the consumer does, even across nodes. CheckIdentity is now wired, in grantsFor.

Also, the minted secret shrinks to 40 chars (30 bytes) from 43: an S3 secret key is
8-40, the same fit-the-tightest-backend rule on the credential's other half.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-05 02:51:39 +02:00
parent b1bf1659d9
commit 9b7ba2e20c
7 changed files with 120 additions and 17 deletions
+1 -1
View File
@@ -57,7 +57,7 @@ func knownFor(m Manifest, needs []Needed, node string) map[string]map[string]str
values := map[string]string{
"at": n.At,
"from": n.From,
"as": ConsumerIdentity(node, m.Module),
"as": ConsumerIdentity(node, IdentitySource(m.Slug, m.Module)),
}
for key, value := range n.Serves {
// The provider's own vocabulary. Rendered plainly: a port is 5432, not 5432.000000,