The vault's seat, and a report that carries the machine's profile (hq ADR 0161)
mesh-vault joins the mesh's own set — mesh-scoped, delivering secret — because the controller seals every minted credential with it, which is the test for a seat of the mesh's own; a second provider is a second claimant, refused by name (issue 106). A report may carry the machine's profile, detected again by the apply that reports, and the latest replaces the enrolled one: a machine that switched its network manager is a machine whose uplink holder lacks a capability at its next push (issue 138).
This commit is contained in:
@@ -75,6 +75,10 @@ var defaultSeats = []Seat{
|
||||
// rather than receives ambiently — 23 of the catalogue's modules never speak, and an ambient
|
||||
// connection would mint a credential for each.
|
||||
{Name: "mesh-broker", Scope: ScopeMesh, Delivers: "mesh-bus", Decision: "novox/hq ADR 0079"},
|
||||
// The vault: the controller seals every minted credential with what it provides, which is the
|
||||
// test for a seat of the mesh's own (novox/hq ADR 0161) — a second provider of `secret` is a
|
||||
// second claimant, refused by name, rather than a candidate for a pin.
|
||||
{Name: "mesh-vault", Scope: ScopeMesh, Delivers: "secret", Decision: "novox/hq ADR 0161"},
|
||||
// Named for its scope since 2026-09-30 (novox/hq ADR 0156); `the-artifact-store` resolves to it as
|
||||
// an alias on a mesh that predates the rename. It serves artifacts of every kind a build makes —
|
||||
// images and archives, by digest — which is why the provision is the artifact store and not an
|
||||
|
||||
@@ -44,7 +44,7 @@ func TestTheSeatsAreAClosedSetAndEachNamesItsDecision(t *testing.T) {
|
||||
delivered[s.Delivers] = s.Name
|
||||
}
|
||||
}
|
||||
if len(Seats()) != 14 {
|
||||
if len(Seats()) != 15 {
|
||||
t.Errorf("the mesh defines %d seats rather than 14; the set is closed, so a change here is "+
|
||||
"a decision (novox/hq ADR 0110): %s", len(Seats()), seatNames())
|
||||
}
|
||||
|
||||
@@ -0,0 +1,25 @@
|
||||
package catalogue
|
||||
|
||||
import "testing"
|
||||
|
||||
// The vault's provision is one the controller itself dereferences — every minted credential is
|
||||
// sealed with it — so it is delivered by a seat of the mesh's own, and a second provider is a second
|
||||
// claimant refused by name rather than a candidate for a pin (novox/hq ADR 0161, issue 106).
|
||||
func TestTheVaultsSeatDeliversSecret(t *testing.T) {
|
||||
seat, known := SeatNamed("mesh-vault")
|
||||
if !known {
|
||||
t.Fatal("mesh-vault is not in the mesh's own set")
|
||||
}
|
||||
if seat.Scope != ScopeMesh || seat.Delivers != "secret" {
|
||||
t.Fatalf("mesh-vault is %s-scoped and delivers %q; one per mesh, delivering secret", seat.Scope, seat.Delivers)
|
||||
}
|
||||
vault := Manifest{Module: "mesh-vault", Provides: []Offer{{Name: "secret", Scope: ScopeMesh}},
|
||||
Claims: []Claim{{Name: "mesh-vault", Scope: ScopeMesh}}}
|
||||
if err := CanHold(vault, seat); err != nil {
|
||||
t.Fatalf("the vault, claiming its seat and providing secret, was refused: %v", err)
|
||||
}
|
||||
another := Manifest{Module: "other-vault", Provides: []Offer{{Name: "secret", Scope: ScopeMesh}}}
|
||||
if err := CanHold(another, seat); err == nil {
|
||||
t.Fatal("a provider of secret that does not claim the seat was allowed to hold it")
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user