Files
mesh-controller/internal/inventory/migrations/0013-a-secret-the-mesh-cannot-reinvent.sql
T
jschoubben 58c8ab7747 A secret the mesh was given is not one the mesh can reinvent
Two kinds live in module_secret and they behaved identically, which is right
for one of them. A made secret is the mesh's: when a node regenerates its
sealing key the mesh makes another and nothing is lost, because nothing else
ever knew the old one.

An accepted secret is not. A broker account's password exists because the
broker was told about it. Regenerating one puts 32 random bytes where a working
credential was — and the machine applies it, reports success, and the program
reading it fails to authenticate somewhere else entirely, with the mesh
insisting the secret was delivered, which it was.

The row now records where the value came from, and a rejoined machine asking
for an accepted one is refused with the remedy named: issue it again. No amount
of pushing produces a password the broker has never heard of.

Found while making the builder a module, which is the first thing to hold one.
2026-08-31 00:32:11 +02:00

17 lines
1006 B
SQL

-- Where a module's own secret came from.
--
-- Two kinds live in this table and they behaved identically, which was wrong in one direction
-- only. A *made* secret is the mesh's: if the node regenerates its sealing key, the mesh makes
-- another and nothing is lost, because nothing else ever knew the old one.
--
-- An *accepted* secret is not the mesh's to invent. A broker account's password exists because
-- the broker was told about it; a licence key exists because somebody bought it. Regenerating one
-- produces 32 random bytes where a working credential used to be -- and the machine applies it,
-- reports success, and the program reading it fails to authenticate somewhere else entirely.
--
-- Everything already here was made by the mesh: accepting one is newer than this table, and the
-- only caller that accepts is the builder's broker account, which is issued per push.
alter table module_secret add column origin text not null default 'made'
check (origin in ('made', 'accepted'));