-- A secret a module needs in order to be itself. -- -- A database has a superuser password, a broker an administrator, a registry an account. None of -- them is *for* anybody -- they are not the credential a consumer is given, and the table holding -- those has a consumer in its key. -- -- **One per node**, so a module running on three machines has three passwords. A manifest that -- carried one instead would put the same secret on every machine that ever runs the module, in a -- file anybody can read, for ever. -- -- Sealed to the node before it is written, like everything else here: what is stored is unusable -- by whoever holds it, the mesh included. create table module_secret ( node uuid not null references node(id) on delete cascade, module text not null references module(name) on delete cascade, -- The module's own word for it. Two secrets in one module are ordinary -- a password and a -- token, say -- and telling them apart is the module's business, not the mesh's. name text not null, sealed text not null, -- Which key it was sealed to, so a node that regenerated its key can be told what it can no -- longer open rather than discovering it as a service that will not start. node_key text not null, made_at timestamptz not null default now(), primary key (node, module, name) );