A provider is told who its consumers are, and a reference provisioner

Contributions were node-local, so a mesh-scoped provider — the one case
that most needs them — never heard from its consumers. A database was
given a password and no idea what to create it for.

Cross-node consumers now reach the provider's `receives` file, merged in
with the ones on its own machine: from the provider's side they are the
same thing, and a provider that had to read two lists would read one of
them. Each names the file its credential is in rather than carrying it,
because the mesh discarded the value and could not put it there. The
readable half therefore stays readable.

And examples/postgres-provisioner, which is the last step: it reads what
the host wrote and makes PostgreSQL accept it. Explicitly not part of the
control plane — the control plane decides and never touches a machine.
This runs on the machine and touches it, and a real one ships with the
module that ships PostgreSQL. It lives here because this is where the
contract is defined, written as something that runs so it can be read.

It reconciles rather than applying a change, because it is never told
what changed. Three things that follow, and each is a fault somebody has
shipped:

- the password is set every time, not only on creation, or a rotation
  reports success and changes nothing
- what it made and nobody asks for any more is revoked, or a departed
  consumer keeps a working login for ever
- what it did not make is left alone, or it cannot be run on a database
  that predates it

Proven in the lab against a real PostgreSQL, each assertion confirmed to
fail with the behaviour removed. The suite is in mesh-lab, which also
records the two ways the test itself was wrong first.
This commit is contained in:
2026-08-30 01:31:25 +02:00
parent 20f78cd5f1
commit c3046dcf56
8 changed files with 455 additions and 11 deletions
+110
View File
@@ -220,3 +220,113 @@ func TestAnEmptyContributionIsRefused(t *testing.T) {
t.Fatalf("the refusal does not say what to do instead: %v", err)
}
}
// A provision answered from anywhere in the mesh has consumers on other machines, and the
// provider has to know who they are. Contributions were node-local until this, which meant the
// one case that most needed them was the one they did not reach.
func provider() Manifest {
return Manifest{Module: "postgres", Version: "1",
Provides: FromAnywhere("database"),
Receives: map[string]string{"database": "/var/lib/postgres/grants/mesh.json"},
Grants: map[string]string{"database": "/var/lib/postgres/grants"},
}
}
// oneGrant is a declaration with a single consumer on another machine.
func oneGrant(t *testing.T) []map[string]any {
t.Helper()
got, err := Resolve(shelf(provider()), []string{"postgres"}, reachable(), World{})
if err != nil {
t.Fatal(err)
}
out, err := got.Declaration(Rendering{Grants: []Grant{{
Provision: "database", Consumer: "workstation", From: "meshboard",
Values: map[string]any{"name": "meshboard"}, Sealed: "c2VhbGVk",
}}})
if err != nil {
t.Fatal(err)
}
return out
}
func grantedTo(t *testing.T, out []map[string]any) []Contribution {
t.Helper()
for _, r := range out {
if r["path"] != "/var/lib/postgres/grants/mesh.json" {
continue
}
var parsed struct {
Given []Contribution `json:"given"`
}
if err := json.Unmarshal([]byte(r["content"].(string)), &parsed); err != nil {
t.Fatal(err)
}
return parsed.Given
}
t.Fatalf("the provider was given no manifest: %v", out)
return nil
}
func TestAProviderIsToldAboutConsumersOnOtherMachines(t *testing.T) {
// A database told to create a password and not who for can do nothing with it.
given := grantedTo(t, oneGrant(t))
if len(given) != 1 {
t.Fatalf("got %v", given)
}
if given[0].Node != "workstation" || given[0].From != "meshboard" {
t.Fatalf("it does not say who asked: %v", given[0])
}
if given[0].Values["name"] != "meshboard" {
t.Fatalf("it does not say what was asked for: %v", given[0].Values)
}
}
func TestTheManifestNamesTheFileRatherThanCarryingTheCredential(t *testing.T) {
// The mesh discarded the value and could not put it here if it wanted to. What is here is
// where to find it — and the readable half therefore stays readable.
out := oneGrant(t)
given := grantedTo(t, out)
if given[0].Secret != "/var/lib/postgres/grants/workstation.secret" {
t.Fatalf("the manifest does not name the credential's file: %q", given[0].Secret)
}
for _, r := range out {
if r["path"] != "/var/lib/postgres/grants/mesh.json" {
continue
}
if strings.Contains(r["content"].(string), "c2VhbGVk") {
t.Fatal("the readable manifest carries the sealed credential")
}
}
}
func TestTheCredentialItselfLandsSealedBesideIt(t *testing.T) {
for _, r := range oneGrant(t) {
if r["path"] != "/var/lib/postgres/grants/workstation.secret" {
continue
}
if r["sealed"] != "c2VhbGVk" {
t.Fatalf("got %v", r)
}
if r["content"] != nil {
t.Fatal("a credential was written in the clear")
}
return
}
t.Fatal("no credential file")
}
func TestAConsumersOwnContributionsAreStillThere(t *testing.T) {
// Cross-node grants are merged in with this machine's own, because from the provider's side
// they are the same thing — somebody wanting something — and a provider that had to read two
// lists would read one of them.
got, err := Resolve(shelf(proxy(), published("board", "board", 8080)),
[]string{"board"}, reachable(), World{})
if err != nil {
t.Fatal(err)
}
given := received(t, mustDeclare(t, got))
if len(given) != 1 || given[0].Node != "" {
t.Fatalf("a local contribution grew a node: %v", given)
}
}