secrets: maps a requirement to several files under local names. Each local name is its own need, its own pair credential (the pair is keyed on it: migration 0027), its own file on the consumer, its own holder at the provider (the identity with the local name after it) and rotates apart from the others. The plain shape is unchanged and every existing row is the credential it was (novox/hq 04-ISSUES/069, ADR 0094).
13 lines
783 B
SQL
13 lines
783 B
SQL
-- A module may need several values from one provider that gives one per pair
|
|
-- (novox/hq 04-ISSUES/069, ADR 0094).
|
|
--
|
|
-- A pair credential was keyed on (provision, consumer node, consumer module, provider): one value
|
|
-- per module per provider. Seven catalogue modules hold two to four independent secrets of their
|
|
-- own -- a root certificate, its key and that key's password -- and the vault could serve each
|
|
-- module one. The pair now carries the LOCAL name the credential goes by inside the module; empty
|
|
-- for the ordinary one, so every existing row is the credential it was.
|
|
|
|
alter table secret add column local text not null default '';
|
|
alter table secret drop constraint secret_pkey;
|
|
alter table secret add primary key (name, local, consumer, consumer_module, provider);
|