diff --git a/internal/catalogue/secrets_into_files.go b/internal/catalogue/secrets_into_files.go index 49e3c3f..b77580a 100644 --- a/internal/catalogue/secrets_into_files.go +++ b/internal/catalogue/secrets_into_files.go @@ -24,9 +24,13 @@ import ( // placeholder is what a module's file content says where a sealed value belongs: ${secret:name}. // -// The same expression the host matches, written out again rather than shared. The two -// repositories agree on a wire format, and a format read on both sides is exactly the thing that -// must not be quietly changed on one of them; a test asserts they still agree. +// The same expression the host matches, written out again rather than shared: they are separate +// repositories and this is a wire format, like the shape of the declaration itself. +// +// **Nothing here can check that they agree, and the claim that something did was wrong.** A unit +// test in this repository can only assert what this repository already believes. What proves it is +// the lab, where a real host receives a real declaration and the file arrives filled — and where +// the two expressions disagreeing shows up as a placeholder written through to a machine. var placeholder = regexp.MustCompile(`\$\{secret:([a-z0-9][a-z0-9-]*)\}`) // secretsUsed are the names a file's content asks for, in the order they first appear.