A provider with one credential shares it with every consumer, remade for all at once (ADR 0158) #184

Merged
mesh-admin merged 1 commits from feat/0158-a-provider-with-one-credential-shares-it into main 2026-10-01 10:27:09 +00:00
Contributor

novox/hq ADR 0158 (forge 243). An offer may say "credential": {"own": "<secret>"}: the provider's own secret is the credential every consumer receives, as a pair credential. One value sealed to the provider, every current consumer and the operator under one generation stamp (migration 0049 adds the column to both tables, text, no new dependency); a consumer binding later or secret rotate on the provider's secret makes a fresh value for every holder in one act, and the rotate command sends every holding machine together. An accepted value is sealed to the consumers of the moment and not remade; a later consumer is refused with the way out. The named own secret must say taken.

Tests: the offer's word and its refusals; a need carrying the shared name on one machine and across machines; the inventory against a raised store — two consumers share the provider's generation, a third binding remakes all, rotation remakes all, an accepted value refuses a later consumer, the holders list. make check fully green.

One release ahead: no catalogue offer says credential yet. The media providers (mesh-media-catalog) follow once this runs, each with taken: at-start and a start that applies the file.

novox/hq ADR 0158 (forge 243). An offer may say `"credential": {"own": "<secret>"}`: the provider's own secret is the credential every consumer receives, as a pair credential. One value sealed to the provider, every current consumer and the operator under one generation stamp (migration 0049 adds the column to both tables, text, no new dependency); a consumer binding later or `secret rotate` on the provider's secret makes a fresh value for every holder in one act, and the rotate command sends every holding machine together. An accepted value is sealed to the consumers of the moment and not remade; a later consumer is refused with the way out. The named own secret must say `taken`. Tests: the offer's word and its refusals; a need carrying the shared name on one machine and across machines; the inventory against a raised store — two consumers share the provider's generation, a third binding remakes all, rotation remakes all, an accepted value refuses a later consumer, the holders list. `make check` fully green. **One release ahead:** no catalogue offer says `credential` yet. The media providers (mesh-media-catalog) follow once this runs, each with `taken: at-start` and a start that applies the file.
mesh-admin added 1 commit 2026-10-01 10:26:57 +00:00
An offer may say `"credential": {"own": "<secret>"}`: the provider's own secret is the credential
every consumer of that provision receives, in the shape of a pair credential. The vault keeps one
value, sealed to the provider, to every consumer that holds the provision and to the operator, all
under one generation stamp; a consumer binding later, or `secret rotate` on the provider's secret,
makes a fresh value and seals it to every holder in one act, and the rotate command sends every
holding machine together. An accepted value is sealed to the consumers of the moment and never
remade: a consumer binding after it is refused with the way out (ADR 0113). The named own secret
must say how it is taken (issue 180), so the provider's start applies the file.

A need carries the shared secret's name from either side of the machine boundary; the plan mints a
consumer's copy from the provider's value. Registered manifests keep their bytes.
mesh-admin merged commit 05ae5e5040 into main 2026-10-01 10:27:09 +00:00
mesh-admin deleted branch feat/0158-a-provider-with-one-credential-shares-it 2026-10-01 10:27:09 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#184