The token says what the mesh calls this machine
Found by raising a mesh end to end for the first time. Enrolment's own help says the token "is the only thing it needs", and it also needed --name, with no default. Without it the failure is: cannot reach the broker at 192.0.2.10:5671 as : username or password not allowed An empty username, and nothing about the cause. The node cannot work its own name out. The broker account it authenticates as is named after it and exists before this machine has been told anything, so the name has to arrive with the rest. It is not a secret and the issuer already knows it. --name stays, as an override for a token issued before the name travelled in one, and says so when it is needed rather than failing at the broker. Also corrects the bundle example, which claimed to stop before the control plane runs and has raised one for some time. A comment about what something does not do is a comment nobody updates.
This commit is contained in:
+12
-8
@@ -2,20 +2,24 @@
|
||||
|
||||
## `substrate-first-node.lock`
|
||||
|
||||
What a machine must be before a mesh exists — steps 0 to 4 of the bootstrap in
|
||||
[novox/hq `07-the-substrate.md`](https://git.novox.be/novox/hq):
|
||||
What a machine must be before a mesh exists — the bootstrap in
|
||||
[novox/hq `07-the-substrate.md`](https://git.novox.be/novox/hq), whole:
|
||||
|
||||
```
|
||||
0 a container runtime
|
||||
1 the store runs
|
||||
2 a database per context one today, `inventory`
|
||||
3 that context's schema mesh-control migrate
|
||||
4 the broker runs
|
||||
2 a database per context `inventory` and `identity`
|
||||
3 those contexts' schemas mesh-control migrate
|
||||
4 the broker runs with a certificate it generated itself
|
||||
5 the control plane runs mesh-control serve
|
||||
```
|
||||
|
||||
**It stops there, and the file says why.** Step 5 is a virtual host, a credential and a
|
||||
certificate; step 6 is the control plane running. Nothing consumes any of them yet, and a bundle
|
||||
whose last step cannot be checked is worse than a shorter one.
|
||||
**A machine that applies this is a mesh** — one node, with nothing joined to it yet, which is
|
||||
exactly what the first node is (novox/hq ADR 0004). From here it hands out tokens and everything
|
||||
else joins the ordinary way.
|
||||
|
||||
This file said it stopped at step 4 for longer than that was true, which is its own small lesson:
|
||||
a comment about what something does not do is a comment nobody updates.
|
||||
|
||||
Build a host carrying it:
|
||||
|
||||
|
||||
@@ -1,9 +1,10 @@
|
||||
// substrate-first-node.lock — what a machine must be before a mesh exists.
|
||||
//
|
||||
// Steps 0 to 5 of the bootstrap (novox/hq 03-DESIGN/01-to-be/07-the-substrate.md): a container
|
||||
// runtime, a store, a database per context, that context's schema, and the broker.
|
||||
// The whole bootstrap (novox/hq 03-DESIGN/01-to-be/07-the-substrate.md): a container runtime, a
|
||||
// store, a database per context, those contexts' schemas, the broker, and the control plane
|
||||
// running on top of them.
|
||||
//
|
||||
// It stops before step 6, where the control plane runs.
|
||||
// It stopped before the control plane once, and this comment said so for longer than it was true.
|
||||
//
|
||||
// The broker generates its OWN certificate, in its own image, into a volume it then mounts read
|
||||
// only. Self-signed, because at this moment there is no mesh to issue one and no public name to
|
||||
|
||||
Reference in New Issue
Block a user