The move mints every credential and tells each machine its membership
`rollout mint` gives every principal the new bus will have a credential it does not yet have and puts each where its owner reads it: a machine's as a membership — bus address, fingerprint, password, transport — sealed into its declaration (migration 0041, the `bus-membership` resource the host reads after applying); a module's as its broker secret, through the same delivery `module issue` uses; the control plane's own as its `bus` secret. Idempotent, and worked out from where the bus's module is assigned rather than from this process's environment, because this process is still on the old bus when it runs and must be. This is the half of design 28 task 5.2 the first live attempt found missing: a credential was minted only at enrolment, at `module issue` and for a person, so no machine already enrolled could ever be moved. `rollout check` was right to refuse; now there is something to run first.
This commit is contained in:
@@ -114,3 +114,32 @@ func TestCanHoldJudgesClaimScopeAndWhatTheSeatDelivers(t *testing.T) {
|
||||
t.Fatalf("with the row saying amqp, an amqp provider was refused: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
// A machine being moved is handed its membership for the new bus as a sealed file in its own
|
||||
// declaration — the machine's, not any module's (design 28, task 5.2).
|
||||
func TestAMembershipForTheNewBusIsComposedAsASealedFile(t *testing.T) {
|
||||
r := Resolution{Node: "anchor"}
|
||||
got, err := r.Compose(Rendering{BusMembership: "sealed-blob"})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
var found map[string]any
|
||||
for _, res := range got.Resources {
|
||||
if res["id"] == BusMembershipID() {
|
||||
found = res
|
||||
}
|
||||
}
|
||||
if found == nil {
|
||||
t.Fatalf("no membership resource in %v", got.Resources)
|
||||
}
|
||||
if found["path"] != BusMembershipPath || found["sealed"] != "sealed-blob" || found["mode"] != "0600" {
|
||||
t.Fatalf("the membership is not a sealed 0600 file where the host reads it: %v", found)
|
||||
}
|
||||
// And a machine not being moved is handed nothing.
|
||||
got, _ = r.Compose(Rendering{})
|
||||
for _, res := range got.Resources {
|
||||
if res["id"] == BusMembershipID() {
|
||||
t.Fatal("a machine with no membership on record was handed one")
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user