A module's own secret rotates when its definition says the module reads it at start (hq 180, forge 231) #183

Merged
mesh-admin merged 1 commits from feat/231-an-own-secret-rotates into main 2026-10-01 09:42:10 +00:00
Contributor

novox/hq issue 180 (forge 231), on ADR 0114's single-party rule.

  • secret rotate <node> <module> <name>: made anew the way the first mint did, sealed to the machine and the operator, the machine sent so the module starts again on it; logged with who asked and when, never the value.
  • An own secret is a path, or {"path": …, "taken": "at-start" | "applied"}. A definition that says nothing of how a secret is taken is refused with the word to write — a credential rotated under software that never reads it again is worse than one left alone (issue 179). applied is refused by name until the staged form is built; a value given to the mesh is refused as ADR 0113 says.
  • rotate is a verb on the controller's seat with two shapes: a pair credential by provision (the existing command), an own secret by machine, module and name. The console can ask.
  • Registered manifests keep their bytes: a path alone is written back as a path.

Tests: the manifest form and its refusals; the rotation against a raised store (rotates at-start; refuses applied, undeclared, accepted, unknown); the verb's two shapes. make check fully green.

One release ahead: no manifest says taken yet; the catalogue follows once this runs. Nothing changes for any module until then.

novox/hq issue 180 (forge 231), on ADR 0114's single-party rule. - `secret rotate <node> <module> <name>`: made anew the way the first mint did, sealed to the machine and the operator, the machine sent so the module starts again on it; logged with who asked and when, never the value. - An own secret is a path, or `{"path": …, "taken": "at-start" | "applied"}`. A definition that says nothing of how a secret is taken is refused with the word to write — a credential rotated under software that never reads it again is worse than one left alone (issue 179). `applied` is refused by name until the staged form is built; a value given to the mesh is refused as ADR 0113 says. - `rotate` is a verb on the controller's seat with two shapes: a pair credential by provision (the existing command), an own secret by machine, module and name. The console can ask. - Registered manifests keep their bytes: a path alone is written back as a path. Tests: the manifest form and its refusals; the rotation against a raised store (rotates at-start; refuses applied, undeclared, accepted, unknown); the verb's two shapes. `make check` fully green. **One release ahead:** no manifest says `taken` yet; the catalogue follows once this runs. Nothing changes for any module until then.
mesh-admin added 1 commit 2026-10-01 09:42:02 +00:00
`secret rotate <node> <module> <name>` makes the secret anew the way the first mint did, seals it
to the machine and the operator, and sends the machine, so the module starts again on the new value
— said in the log with who asked and when, never the value. Only for a secret whose definition says
`"taken": "at-start"`: an own secret is now a path, or {path, taken}, and a definition that says
nothing of how a secret is taken is refused with the word to write, because a credential rotated
under software that never reads it again is worse than one left alone (issue 179). `applied` is
refused by name until the staged form ADR 0114 decided is built; a value given to the mesh is
refused as ADR 0113 says. `rotate` is a verb on the controller's seat with two shapes — a pair
credential by provision, an own secret by machine, module and name — so the console can ask.
Registered manifests keep their bytes: a path alone is written back as a path.
mesh-admin merged commit 6ca4ba68c8 into main 2026-10-01 09:42:10 +00:00
mesh-admin deleted branch feat/231-an-own-secret-rotates 2026-10-01 09:42:10 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#183