-- The authority that certifies names inside the mesh. -- -- novox/hq 08-connectivity keeps two authorities apart on purpose: a public one issues for names -- the outside world reaches, and this one issues for names only the mesh knows. Collapsing them -- would mean a public authority being asked to certify a name it cannot verify, and a mesh -- authority being trusted by things outside it. -- -- **It is not a bootstrap concern.** A joining node verifies the control plane against the -- fingerprint in its token, so nothing needs this before membership. It certifies internal names -- afterwards, and that is all it does. create table authority ( -- One row, like the signing key beside it. Two authorities and nothing says which certificate -- to believe. singleton boolean primary key default true check (singleton), certificate text not null, -- The private half. Held here because signing is what this context is for -- the same -- reasoning as the signing key, which is also held and also never leaves. private text not null, made_at timestamptz not null default now() ); -- What a node serves TLS with, and what was issued for it. -- -- The public half only. The node generated the pair and keeps the private one, so a copy of this -- table certifies nothing and impersonates nobody -- which is the same property the node keys -- table has, for the same reason. alter table node_key add column serving_key text; alter table node_key add column certificate text; alter table node_key add column certified_at timestamptz;