novox/hq ADR 0085 (amended), design 24, issue 071. Merge first of five (mesh-controller → mesh-catalog → mesh-host → mesh-lab → hq).
operator key make (offline) / set / show: an operator sealing key whose private half never enters the mesh.
Every own secret and every pair credential is sealed a second time to that key (migrations 0023, 0024); secrets made before the key exist are listed as unrecoverable, those sealed to a replaced key as such.
secret recover <node> <module> <name> --key … [--from-export …] [--provider …] opens one with the operator's key, to a 0600 file; secret export writes every operator-sealed copy as ciphertext.
Manifest keeps: a module that keeps the export (the vault) is handed it as a declared file on its own disk, so recovery survives the store.
Proven by mesh-lab assigned-vault.test.ts (3/3) and one-node-mesh.test.ts (22/22) on this branch set. Reviewed; three bookkeeping bugs found and fixed in 77e6c1a.
novox/hq ADR 0085 (amended), design 24, issue 071. Merge first of five (mesh-controller → mesh-catalog → mesh-host → mesh-lab → hq).
- `operator key make` (offline) / `set` / `show`: an operator sealing key whose private half never enters the mesh.
- Every own secret and every pair credential is sealed a second time to that key (migrations 0023, 0024); secrets made before the key exist are listed as unrecoverable, those sealed to a replaced key as such.
- `secret recover <node> <module> <name> --key … [--from-export …] [--provider …]` opens one with the operator's key, to a 0600 file; `secret export` writes every operator-sealed copy as ciphertext.
- Manifest `keeps`: a module that keeps the export (the vault) is handed it as a declared file on its own disk, so recovery survives the store.
Proven by mesh-lab `assigned-vault.test.ts` (3/3) and `one-node-mesh.test.ts` (22/22) on this branch set. Reviewed; three bookkeeping bugs found and fixed in 77e6c1a.
novox/hq ADR 0085, amended: the mesh's root secrets — the store's superuser,
the broker's administrator, every secret a module holds for itself — were
sealed to a node key and nothing else, so a lost node took them with it.
Now the mesh records an operator's public sealing key and seals every own
secret to it as well, minted or accepted. The private half is written once
by `operator key new` to a file the operator keeps off the mesh; the mesh
holds one more blob per secret that it cannot open.
`secret recover` opens a secret with that key, to a 0600 file, from the
store or from an export; `secret export` writes every operator-sealed copy
as ciphertext. A module that `keeps` (the vault) is handed that export as a
declared file on its own disk, so recovery survives the store.
Secrets made before the key exists have no operator copy and are said so —
the plaintext was discarded — until each is issued again.
The secret the vault provides a module is the credential of the consumer↔vault
pair, and so is every credential a provider grants; sealing only own secrets
to the operator left exactly those unrecoverable. Same column, same call; the
export and `secret recover` address a pair by consumer node, module and the
provision's name, and say which kind each entry is.
From review: the export counted any operator-sealed row as recoverable, so a
secret sealed to a replaced key was reported as openable with the current one;
replacing the key counted orphans in one table of two; and a pair credential
held from two providers was recovered as whichever row came first. The export
now lists what the current key opens, what an earlier key opens, and what has
no copy; `secret recover` takes --provider and refuses ambiguity; files that
must not exist are created exclusively; one constructor builds the export for
the operator's file and the vault's disk alike.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
novox/hq ADR 0085 (amended), design 24, issue 071. Merge first of five (mesh-controller → mesh-catalog → mesh-host → mesh-lab → hq).
operator key make(offline) /set/show: an operator sealing key whose private half never enters the mesh.secret recover <node> <module> <name> --key … [--from-export …] [--provider …]opens one with the operator's key, to a 0600 file;secret exportwrites every operator-sealed copy as ciphertext.keeps: a module that keeps the export (the vault) is handed it as a declared file on its own disk, so recovery survives the store.Proven by mesh-lab
assigned-vault.test.ts(3/3) andone-node-mesh.test.ts(22/22) on this branch set. Reviewed; three bookkeeping bugs found and fixed in77e6c1a.