Multiple fixes: a run-once step may name what it reads (ADR 0099); secret accept refuses an undeclared name (078) #40

Merged
jschoubben merged 4 commits from multiple-fixes into main 2026-09-21 21:58:47 +00:00
Showing only changes of commit 66332705cd - Show all commits
+7
View File
@@ -253,6 +253,13 @@ func moduleCommand(ctx context.Context, args []string) error {
if !ok {
return fmt.Errorf("this mesh knows no module %q; `module add` it first", module)
}
// The account is delivered as the module's own secret named broker; a module that declares
// none has nothing to read it with, and an account nothing reads is an orphan on the bus
// (novox/hq 04-ISSUES/078). Said before the account is made, not after.
if _, reads := m.OwnSecrets["broker"]; !reads {
return fmt.Errorf("%s declares no own secret named broker, so there is nowhere to deliver "+
"an account; a module that speaks on the bus declares \"own-secrets\": {\"broker\": <path>}", module)
}
management, err := broker.ManagementFromEnvironment()
if err != nil {