-- The operator's sealing key, and a second seal on every secret a module holds for itself. -- -- Every secret here is sealed to the node that will use it and to nothing else, so a node whose key -- is gone takes its secrets with it -- and the mesh's own root secrets, the store's superuser and -- the broker's administrator among them, are exactly such secrets. novox/hq ADR 0085 (amended) -- gives them a second holder: a person, with a key whose private half never enters the mesh. What -- the mesh keeps is one more blob it cannot open. -- At most one operator key at a time. A row rather than a setting, because it is a fact about the -- mesh with consequences (what can be recovered), not somebody's preference about a module. create table operator_key ( public text not null primary key, made_at timestamptz not null default now() ); alter table module_secret -- The same value, sealed to the operator key -- null for a secret minted before there was -- one, which cannot be sealed after the fact: the plaintext was discarded. Such a secret is -- recoverable only once it is issued again. add column operator_sealed text, -- Which operator key, so a replaced key can be told what it can no longer open. add column operator_key text;