A token is an account on the bus, and genesis can place the list
novox/hq 04-ISSUES/146. The composed user list names an enrolment user for every machine with a live token and nothing minted a credential for it, so the composer left it out as a user with no password — and every enrolment since the mesh moved to this bus was refused before the mesh heard of it. The comment above the issuing code already said the account is created before the token is handed over; now it is. Recorded rather than minted, because the token's secret is the password. And 'broker accounts', which composes the same list the declaration carries and writes it to standard output. For genesis, where no declaration can reach the machine running the bus because that machine is not yet a node. It says what it composed; whoever is raising the machine places it. A control plane that wrote the file itself would have to learn where the bus keeps its configuration and how to make it reload, which is the module's knowledge.
This commit is contained in:
@@ -14,6 +14,7 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/jackc/pgx/v5"
|
||||
"github.com/novox/mesh-controller/internal/broker"
|
||||
"github.com/novox/mesh-controller/internal/store"
|
||||
)
|
||||
|
||||
@@ -263,6 +264,29 @@ func (i *Inventory) IssueToken(ctx context.Context, nodeName string, validFor ti
|
||||
return Issued{}, err
|
||||
}
|
||||
|
||||
// **And the account that secret is the password of** (novox/hq 04-ISSUES/146). The composed
|
||||
// user list names an enrolment user for every node with a live token, and nothing minted a
|
||||
// credential for it — so the composer left it out as a user with no password and every
|
||||
// enrolment was refused by the server before the mesh heard of it.
|
||||
//
|
||||
// Recorded rather than minted: the token's secret IS the password, which is what lets a
|
||||
// machine's first connection be authenticated by the thing it is enrolling with. It cannot be
|
||||
// chosen here, because it has already been handed to whoever will present it.
|
||||
//
|
||||
// Outside the transaction on purpose. The token is what the mesh promised; a credential that
|
||||
// the next composition rewrites anyway is not worth failing an issue over, and a token with no
|
||||
// account is recoverable by issuing another, while an account with no token is a user nobody
|
||||
// can be.
|
||||
if err := i.RecordBusPassword(ctx, BusUser{
|
||||
Username: broker.Principal{Kind: broker.KindEnrolment, Node: node.Name}.Username(),
|
||||
Kind: BusEnrolment,
|
||||
Node: node.Name,
|
||||
}, secret); err != nil {
|
||||
return Issued{}, fmt.Errorf(
|
||||
"the token for %s was issued and the bus account it is the password of was not "+
|
||||
"recorded, so this token cannot connect: %w", node.Name, err)
|
||||
}
|
||||
|
||||
return Issued{Node: node, Secret: secret, Expires: expires}, nil
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user