A secret reaches a process as a file (ADR 0086, closes issue 041) #35

Merged
jschoubben merged 3 commits from feat/secret-not-in-environment into main 2026-09-21 09:59:02 +00:00
3 Commits
Author SHA1 Message Date
jschoubben 67de216160 The controller's own manifest reads its credentials from files too
The mesh-controller repository carries the manifest the mesh builds the
controller from; the catalogue's copy is what genesis registers. The two must
say the same thing, and the first rebuild from source proved they did not.
2026-09-21 10:33:22 +02:00
jschoubben 69bb0fcb67 A module names who its secret files belong to (secrets-owner)
The control plane runs as 65534 and crash-looped on permission denied the
first time its credentials were mounted as files the host wrote as root at
0600 — the env-file shape hid this because the daemon reads an env-file on
the host side. The composer now gives a module's secret files the owner the
manifest names.
2026-09-21 10:19:00 +02:00
jschoubben 4531f2244f A secret reaches a process as a file (ADR 0086)
The broker settings take a _FILE twin like the store connections; the
catalogue engine refuses a secret placeholder in a container's env and a
secret-carrying env-file unless the container says why with
secrets-in-environment, which stays in the catalogue and never reaches the
machine.
2026-09-21 10:10:33 +02:00