-- A value given to the mesh for a secret it may make lives only until the module's first good start -- (novox/hq ADR 0228). -- -- A person gives a module's own secret by hand for one reason: to adopt something already running -- that holds that value. Once the module has started under the mesh on it, the value has done its -- work, and the mesh puts one of its own in its place — made, sealed and sent as any value it makes, -- so nothing a person ever handled is left in force. -- -- When the value was given, for a given value awaiting that replacement; null for every other row — -- a value the mesh made, one an outside party issued, one a module applies to a backend, and every -- value given before this column existed, which `secret rotate` replaces when a person asks. The -- replacement waits for a clean report of a declaration sent after this moment, so it is the start -- on the given value that is waited for, not an older one; and it clears the column, so it happens -- once. alter table module_secret add column replace_after_start timestamptz;