The control plane declares, and hears back
`declare` sends a node a signed declaration; `serve` now also consumes reports. Signed over the exact bytes published, which is what the node verifies. Anything re-encoding in between would sign one thing and check another, and a difference in key order alone would have a node refuse a declaration that was genuinely the mesh's. Sent to the node's queue directly rather than through the exchange: a declaration is for one node, and routing by name through a shared exchange means a binding per node that nothing removes when a node is retired. Enrolment now issues the node its own broker password, replacing the token's secret, and tells it the broker address, the fingerprint and the signing key -- so a node can reconnect after a restart without a person and a new token, which is what makes disconnection ordinary rather than a crisis. A report is a statement, not a write. What a node says it applied is its own account of its own machine, kept as a copy for recovery rather than as a source.
This commit is contained in:
@@ -15,7 +15,8 @@ const ControlQueue = "control"
|
||||
// Routing keys. A node may publish these; it may not publish anything else, because its broker
|
||||
// account is scoped to this exchange and its own queue.
|
||||
const (
|
||||
KeyEnrol = "enrol"
|
||||
KeyEnrol = "enrol"
|
||||
KeyReport = "report"
|
||||
)
|
||||
|
||||
// QueueFor is the queue a node consumes from — the only one it may read.
|
||||
@@ -44,6 +45,24 @@ type EnrolRequest struct {
|
||||
Profile map[string]any `json:"profile,omitempty"`
|
||||
}
|
||||
|
||||
// Signed is a declaration and the signature over it.
|
||||
//
|
||||
// The signature is over Declaration exactly as it will arrive, bytes unchanged — a node verifies
|
||||
// what it received rather than what it re-encoded, because any difference in key order or spacing
|
||||
// would break a signature over the same meaning.
|
||||
type Signed struct {
|
||||
Declaration []byte `json:"declaration"`
|
||||
Signature []byte `json:"signature"`
|
||||
}
|
||||
|
||||
// Report is what a node states after applying. It states; the owning context writes.
|
||||
type Report struct {
|
||||
Node string `json:"node"`
|
||||
Applied []string `json:"applied,omitempty"`
|
||||
Failed map[string]string `json:"failed,omitempty"`
|
||||
Refused string `json:"refused,omitempty"`
|
||||
}
|
||||
|
||||
// EnrolReply is what the mesh says back.
|
||||
type EnrolReply struct {
|
||||
// Accepted says whether the node is now known.
|
||||
@@ -57,6 +76,17 @@ type EnrolReply struct {
|
||||
// Queue is where this node listens from now on.
|
||||
Queue string `json:"queue,omitempty"`
|
||||
|
||||
// Password is this node's own broker account from now on, replacing the token's secret.
|
||||
// A credential that lives for as long as the node should not be the same string as one that
|
||||
// was meant to be used once.
|
||||
Password string `json:"password,omitempty"`
|
||||
|
||||
// Fingerprint and Signer are what the node keeps so it can reconnect and keep verifying
|
||||
// without a person and a new token.
|
||||
Fingerprint string `json:"fingerprint,omitempty"`
|
||||
Signer []byte `json:"signer,omitempty"`
|
||||
Broker string `json:"broker,omitempty"`
|
||||
|
||||
// Refusal says why not, in words for a person. Deliberately the same for every reason a
|
||||
// token can fail — unknown, spent, expired — so that guessing learns nothing.
|
||||
Refusal string `json:"refusal,omitempty"`
|
||||
|
||||
Reference in New Issue
Block a user