Replace a value given by hand like one the mesh made (hq ADR 0228)
A given own secret the module reads at start is held by nobody but that module, so the mesh need not read it to replace it: secret rotate now works on it, and a value given through secret accept is replaced on its own after the module's first good start under the mesh. Only a value an outside party issues (own-secrets "issued-by": "outside") or one the module applies stays as given, refused with the reason.
This commit is contained in:
+15
@@ -0,0 +1,15 @@
|
||||
-- A value given to the mesh for a secret it may make lives only until the module's first good start
|
||||
-- (novox/hq ADR 0228).
|
||||
--
|
||||
-- A person gives a module's own secret by hand for one reason: to adopt something already running
|
||||
-- that holds that value. Once the module has started under the mesh on it, the value has done its
|
||||
-- work, and the mesh puts one of its own in its place — made, sealed and sent as any value it makes,
|
||||
-- so nothing a person ever handled is left in force.
|
||||
--
|
||||
-- When the value was given, for a given value awaiting that replacement; null for every other row —
|
||||
-- a value the mesh made, one an outside party issued, one a module applies to a backend, and every
|
||||
-- value given before this column existed, which `secret rotate` replaces when a person asks. The
|
||||
-- replacement waits for a clean report of a declaration sent after this moment, so it is the start
|
||||
-- on the given value that is waited for, not an older one; and it clears the column, so it happens
|
||||
-- once.
|
||||
alter table module_secret add column replace_after_start timestamptz;
|
||||
Reference in New Issue
Block a user