mesh-vault joins the mesh's own set — mesh-scoped, delivering secret — because the controller seals every minted credential with it, which is the test for a seat of the mesh's own; a second provider is a second claimant, refused by name (issue 106). A report may carry the machine's profile, detected again by the apply that reports, and the latest replaces the enrolled one: a machine that switched its network manager is a machine whose uplink holder lacks a capability at its next push (issue 138).
26 lines
1.2 KiB
Go
26 lines
1.2 KiB
Go
package catalogue
|
|
|
|
import "testing"
|
|
|
|
// The vault's provision is one the controller itself dereferences — every minted credential is
|
|
// sealed with it — so it is delivered by a seat of the mesh's own, and a second provider is a second
|
|
// claimant refused by name rather than a candidate for a pin (novox/hq ADR 0161, issue 106).
|
|
func TestTheVaultsSeatDeliversSecret(t *testing.T) {
|
|
seat, known := SeatNamed("mesh-vault")
|
|
if !known {
|
|
t.Fatal("mesh-vault is not in the mesh's own set")
|
|
}
|
|
if seat.Scope != ScopeMesh || seat.Delivers != "secret" {
|
|
t.Fatalf("mesh-vault is %s-scoped and delivers %q; one per mesh, delivering secret", seat.Scope, seat.Delivers)
|
|
}
|
|
vault := Manifest{Module: "mesh-vault", Provides: []Offer{{Name: "secret", Scope: ScopeMesh}},
|
|
Claims: []Claim{{Name: "mesh-vault", Scope: ScopeMesh}}}
|
|
if err := CanHold(vault, seat); err != nil {
|
|
t.Fatalf("the vault, claiming its seat and providing secret, was refused: %v", err)
|
|
}
|
|
another := Manifest{Module: "other-vault", Provides: []Offer{{Name: "secret", Scope: ScopeMesh}}}
|
|
if err := CanHold(another, seat); err == nil {
|
|
t.Fatal("a provider of secret that does not claim the seat was allowed to hold it")
|
|
}
|
|
}
|