The vault's seat, and a report that carries the machine's profile (hq ADR 0161)
mesh-vault joins the mesh's own set — mesh-scoped, delivering secret — because the controller seals every minted credential with it, which is the test for a seat of the mesh's own; a second provider is a second claimant, refused by name (issue 106). A report may carry the machine's profile, detected again by the apply that reports, and the latest replaces the enrolled one: a machine that switched its network manager is a machine whose uplink holder lacks a capability at its next push (issue 138).
This commit is contained in:
@@ -320,6 +320,13 @@ func (e Enrolment) Heard(ctx context.Context, report Report) (news bool, err err
|
||||
return false, err
|
||||
}
|
||||
}
|
||||
if len(report.Profile) > 0 {
|
||||
// The latest wins, as at enrolment: a capability the machine lost is one the plan must
|
||||
// stop counting on (novox/hq ADR 0161).
|
||||
if err := e.Inventory.RecordProfile(ctx, node.ID, report.Profile); err != nil {
|
||||
return false, err
|
||||
}
|
||||
}
|
||||
// What it says about the tunnel it carried (novox/hq ADR 0105), whenever it says it.
|
||||
if report.Tunnel != nil {
|
||||
if err := e.Inventory.RecordCarriedTunnel(ctx, node.ID, inventory.Carried{
|
||||
|
||||
Reference in New Issue
Block a user