Four issues on one branch, one commit group each, one decision record each (hq MR on the same branch name).
069 — several secrets from one provider (ADR 0094)
secrets: maps a requirement to several files under local names. Each local name is its own need (expanded in the per-consumer pass, where the consumer is known), its own pair credential (migration 0027 adds local to the key; every existing row keeps ''), its own file on the consumer (${secret:<local>}), its own holder at the provider (<identity>_<local>, its own grant file), and rotates apart. rotate and secret accept --provider --local carry it. Along the way: a need is now kept once per (provision, consumer, local, provider) — two consumers of one same-node provision used to produce the same credential twice for each.
049 — the control plane is the way to ask (ADR 0095)
ask <module> <tool> [json] publishes on mesh.rpc with a private reply queue bound under its own name, checks the correlation, prints the answer, exits non-zero for a tool that answered with an error or a module that never answered.
046 — an upstream image is copied between registries (ADR 0096)
The builder reads the index and every manifest it names over the registry API (anonymous bearer token on challenge), moves each blob by digest into the mesh's registry, puts the manifests and then the index under the module's repository, and pins the index. Genesis keeps the pull. Tested against a fake upstream serving an index over two platforms and a fake mesh registry.
064 — a vendor image is a declared build input (ADR 0097)
build.on takes {arg, image@sha256:…}; the image is copied in before the build and handed to the recipe. A COPY --from of an undeclared registry image is refused before the build; an undeclared FROM is said, not refused — the mesh's own images start FROM a public base, and refusing them refuses genesis. The package half of 064 stays open (needs a rerun).
Proven
go test ./... green with MESH_TEST_POSTGRES. Lab, against a controller image built from this branch: assigned-vault 4/4 with a two-secrets consumer (two values, two ledger holders, both rotated); assigned-tools-confluence green including an ask through the control plane that got the tool's answer.
Four issues on one branch, one commit group each, one decision record each (hq MR on the same branch name).
## 069 — several secrets from one provider (ADR 0094)
`secrets:` maps a requirement to several files under local names. Each local name is its own need (expanded in the per-consumer pass, where the consumer is known), its own pair credential (migration 0027 adds `local` to the key; every existing row keeps `''`), its own file on the consumer (`${secret:<local>}`), its own holder at the provider (`<identity>_<local>`, its own grant file), and rotates apart. `rotate` and `secret accept --provider --local` carry it. Along the way: a need is now kept once per (provision, consumer, local, provider) — two consumers of one same-node provision used to produce the same credential twice for each.
## 049 — the control plane is the way to ask (ADR 0095)
`ask <module> <tool> [json]` publishes on `mesh.rpc` with a private reply queue bound under its own name, checks the correlation, prints the answer, exits non-zero for a tool that answered with an error or a module that never answered.
## 046 — an upstream image is copied between registries (ADR 0096)
The builder reads the index and every manifest it names over the registry API (anonymous bearer token on challenge), moves each blob by digest into the mesh's registry, puts the manifests and then the index under the module's repository, and pins the index. Genesis keeps the pull. Tested against a fake upstream serving an index over two platforms and a fake mesh registry.
## 064 — a vendor image is a declared build input (ADR 0097)
`build.on` takes `{arg, image@sha256:…}`; the image is copied in before the build and handed to the recipe. A `COPY --from` of an undeclared registry image is refused before the build; an undeclared `FROM` is said, not refused — the mesh's own images start FROM a public base, and refusing them refuses genesis. The package half of 064 stays open (needs a rerun).
## Proven
`go test ./...` green with `MESH_TEST_POSTGRES`. Lab, against a controller image built from this branch: assigned-vault 4/4 with a two-secrets consumer (two values, two ledger holders, both rotated); assigned-tools-confluence green including an `ask` through the control plane that got the tool's answer.
secrets: maps a requirement to several files under local names. Each local name is
its own need, its own pair credential (the pair is keyed on it: migration 0027),
its own file on the consumer, its own holder at the provider (the identity with the
local name after it) and rotates apart from the others. The plain shape is
unchanged and every existing row is the credential it was (novox/hq 04-ISSUES/069,
ADR 0094).
A module serves tools under an account scoped to exactly that, and nothing else in
the mesh held an account that could ask one. The control plane does: ask publishes
on the RPC exchange with a private reply queue bound under its own name, checks the
correlation, prints the answer, and exits non-zero for a tool that answered with an
error or a module that never answered (novox/hq 04-ISSUES/049, ADR 0095).
The lab's two-secrets consumer was given one credential and no file: the expansion
ran on the resolver's walk over names, on whichever module mentioned the provision
first, and the per-consumer pass copied that. It expands in that pass now, and a
test has two consumers of one provision, one keeping one file and one keeping two.
Two consumers of one same-node provision produced two raw needs and, fanned out per
consumer, four — the same credential twice for each. Harmless, since a pair is one
row however often it is asked for, and wrong all the same.
The lab's vault refused a declaration naming two files with one identity: the
two secrets of one consumer. The holder's suffix is in the resource id and the path now.
A published image is an index over several architectures; pulled, the runtime's
store keeps the index and refuses to push one platform out of it. The builder now
reads the index and every manifest it names over the registry API, with the
anonymous bearer token the public hub hands out, moves each blob by digest into the
mesh's registry, puts the manifests and then the index under the module's repository,
and pins the index. Genesis, with no registry to copy into, keeps the pull
(novox/hq 04-ISSUES/046, ADR 0096).
build.on takes {arg, image@sha256:…} beside {arg, module, artifact}: the image is
copied into the mesh's registry before the build (ADR 0096) and the recipe reads the
copy from the argument. A FROM or COPY --from naming a registry image the manifest
did not declare is refused before the build, naming it and the remedy; stages,
declared arguments and scratch are not fetches (novox/hq 04-ISSUES/064, ADR 0097).
The mesh's own images start FROM a public base — the control plane's, the builder's,
the tool runtime's — and refusing those refuses genesis. They declare their bases
next; until then the base is named every build, with the remedy.
A secrets object with one local name delivered no file. Two requirements could share
a local name. secret recover and the export could not tell two locals apart. The
recipe check missed continued lines and read heredoc bodies as bases. repo:tag@digest
kept the tag in the repository. ask now publishes mandatory, so a tool nothing serves
is said at once rather than after the wait.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Four issues on one branch, one commit group each, one decision record each (hq MR on the same branch name).
069 — several secrets from one provider (ADR 0094)
secrets:maps a requirement to several files under local names. Each local name is its own need (expanded in the per-consumer pass, where the consumer is known), its own pair credential (migration 0027 addslocalto the key; every existing row keeps''), its own file on the consumer (${secret:<local>}), its own holder at the provider (<identity>_<local>, its own grant file), and rotates apart.rotateandsecret accept --provider --localcarry it. Along the way: a need is now kept once per (provision, consumer, local, provider) — two consumers of one same-node provision used to produce the same credential twice for each.049 — the control plane is the way to ask (ADR 0095)
ask <module> <tool> [json]publishes onmesh.rpcwith a private reply queue bound under its own name, checks the correlation, prints the answer, exits non-zero for a tool that answered with an error or a module that never answered.046 — an upstream image is copied between registries (ADR 0096)
The builder reads the index and every manifest it names over the registry API (anonymous bearer token on challenge), moves each blob by digest into the mesh's registry, puts the manifests and then the index under the module's repository, and pins the index. Genesis keeps the pull. Tested against a fake upstream serving an index over two platforms and a fake mesh registry.
064 — a vendor image is a declared build input (ADR 0097)
build.ontakes{arg, image@sha256:…}; the image is copied in before the build and handed to the recipe. ACOPY --fromof an undeclared registry image is refused before the build; an undeclaredFROMis said, not refused — the mesh's own images start FROM a public base, and refusing them refuses genesis. The package half of 064 stays open (needs a rerun).Proven
go test ./...green withMESH_TEST_POSTGRES. Lab, against a controller image built from this branch: assigned-vault 4/4 with a two-secrets consumer (two values, two ledger holders, both rotated); assigned-tools-confluence green including anaskthrough the control plane that got the tool's answer.build.on takes {arg, image@sha256:…} beside {arg, module, artifact}: the image is copied into the mesh's registry before the build (ADR 0096) and the recipe reads the copy from the argument. A FROM or COPY --from naming a registry image the manifest did not declare is refused before the build, naming it and the remedy; stages, declared arguments and scratch are not fetches (novox/hq 04-ISSUES/064, ADR 0097).