The give verb opened the desk's hidden prompt for a module's own secret, with the desk named. Now the secret-ask verb (secret ask <node> <module> <name> [--at <desk>]) opens the same prompt from anywhere on the mesh, with the desk the module's machine unless named, and give composes the same line. Every ask is recorded in the store before the prompt opens (migration 0091): one open ask per secret, three an hour, so an agent cannot keep a prompt in front of the operator. The prompt names who asked, from the bus's word on the caller cut to a name's characters, never an argument of the call. The value stays typed at the desk, sealed to the one call and then to the module's machine, never in an argument, a log or an event; a secret the mesh makes itself and a trusted party's secret are refused as before.
165 lines
4.0 KiB
JSON
165 lines
4.0 KiB
JSON
{
|
|
"module": "mesh-controller",
|
|
"version": "1",
|
|
"slug": "control",
|
|
"claims": [
|
|
{
|
|
"name": "mesh-controller",
|
|
"scope": "mesh"
|
|
}
|
|
],
|
|
"accesses": [
|
|
{
|
|
"path": "/var/lib/mesh-broker-tls",
|
|
"mode": "read"
|
|
}
|
|
],
|
|
"own-secrets": {
|
|
"inventory": "${dir:mesh-state}/inventory",
|
|
"identity": "${dir:mesh-state}/identity",
|
|
"licences": "${dir:mesh-state}/licences",
|
|
"broker": "${dir:mesh-state}/broker",
|
|
"broker-management": "${dir:mesh-state}/broker-management",
|
|
"broker-address": "${dir:mesh-state}/broker-address",
|
|
"bus": "${dir:mesh-state}/bus"
|
|
},
|
|
"secrets-owner": "mesh-controller",
|
|
"prepares": true,
|
|
"settings": {
|
|
"merge-window": {
|
|
"kind": "preference",
|
|
"default": "90s",
|
|
"why": "merges are collected while they keep coming, and a batch is planned once no merge came for this long (novox/hq ADR 0276)"
|
|
},
|
|
"merge-window-at-most": {
|
|
"kind": "preference",
|
|
"default": "10m",
|
|
"why": "a busy period never holds a batch longer than this after its first merge (novox/hq ADR 0276)"
|
|
}
|
|
},
|
|
"tools": [
|
|
"tools",
|
|
"calls",
|
|
"status",
|
|
"nodes",
|
|
"node",
|
|
"modules",
|
|
"seats",
|
|
"builds",
|
|
"plans",
|
|
"delivery-plan",
|
|
"delivery-order",
|
|
"delivery-check",
|
|
"deliver",
|
|
"delivery-stop",
|
|
"delivery-walks",
|
|
"plan",
|
|
"assign",
|
|
"unassign",
|
|
"pin",
|
|
"unpin",
|
|
"push",
|
|
"rotate",
|
|
"give",
|
|
"issue",
|
|
"token",
|
|
"settings",
|
|
"command",
|
|
"queue",
|
|
"cancel",
|
|
"clear",
|
|
"rebuild",
|
|
"replay",
|
|
"kill",
|
|
"pause",
|
|
"resume",
|
|
"hand-act",
|
|
"drill",
|
|
"warranted",
|
|
"secret-ask",
|
|
"hand-acts",
|
|
"durations",
|
|
"conditions",
|
|
"healers",
|
|
"doctor",
|
|
"upgrade",
|
|
"bus",
|
|
"retire",
|
|
"cleanup",
|
|
"dead-letters",
|
|
"root-free",
|
|
"data",
|
|
"build",
|
|
"artifacts",
|
|
"collect",
|
|
"images",
|
|
"mirrors"
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "account",
|
|
"type": "user",
|
|
"name": "mesh-controller",
|
|
"shell": "/usr/bin/nologin",
|
|
"home": "/var/lib/mesh-controller"
|
|
},
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "mesh",
|
|
"owner": "mesh-controller"
|
|
},
|
|
{
|
|
"id": "merge-window",
|
|
"type": "file",
|
|
"path": "${dir:mesh-state}/merge-window.json",
|
|
"mode": "0600",
|
|
"owner": "mesh-controller",
|
|
"content": "{\n \"merge-window\": \"${setting:merge-window}\",\n \"merge-window-at-most\": \"${setting:merge-window-at-most}\"\n}\n"
|
|
},
|
|
{
|
|
"id": "controller",
|
|
"type": "process",
|
|
"name": "mesh-controller",
|
|
"artifact": "controller",
|
|
"run": [
|
|
"./mesh-controller",
|
|
"serve"
|
|
],
|
|
"user": "mesh-controller",
|
|
"env": {
|
|
"MESH_BROKER_CERTIFICATE": "/var/lib/mesh-broker-tls/tls.crt",
|
|
"MESH_STORE_INVENTORY_FILE": "${dir:mesh-state}/inventory",
|
|
"MESH_STORE_IDENTITY_FILE": "${dir:mesh-state}/identity",
|
|
"MESH_STORE_LICENCES_FILE": "${dir:mesh-state}/licences",
|
|
"MESH_BROKER_MANAGEMENT_FILE": "${dir:mesh-state}/broker-management",
|
|
"MESH_BROKER_ADDRESS_FILE": "${dir:mesh-state}/broker-address",
|
|
"MESH_STORE_INVENTORY_PORT": "${seat:mesh-store:5432}",
|
|
"MESH_STORE_IDENTITY_PORT": "${seat:mesh-store:5432}",
|
|
"MESH_STORE_LICENCES_PORT": "${seat:mesh-store:5432}",
|
|
"MESH_BROKER_MANAGEMENT_PORT": "${seat:mesh-broker:15672}",
|
|
"MESH_BROKER_ADDRESS_PORT": "${seat:mesh-broker:5671}",
|
|
"MESH_BUS_NATS_FILE": "${dir:mesh-state}/bus",
|
|
"MESH_CONTROLLER_VERSION": "${version}",
|
|
"MESH_MERGE_WINDOW_FILE": "${dir:mesh-state}/merge-window.json"
|
|
},
|
|
"replaces": [
|
|
"server"
|
|
]
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "controller",
|
|
"kind": "bundle",
|
|
"language": "go",
|
|
"system": "arch",
|
|
"from": "cmd/mesh-controller",
|
|
"binary": "mesh-controller"
|
|
}
|
|
]
|
|
}
|
|
}
|