The token says what the mesh calls this machine

Found by raising a mesh end to end for the first time. Enrolment's own
help says the token "is the only thing it needs", and it also needed
--name, with no default. Without it the failure is:

  cannot reach the broker at 192.0.2.10:5671 as : username or password
  not allowed

An empty username, and nothing about the cause.

The node cannot work its own name out. The broker account it
authenticates as is named after it and exists before this machine has
been told anything, so the name has to arrive with the rest. It is not a
secret and the issuer already knows it.

--name stays, as an override for a token issued before the name
travelled in one, and says so when it is needed rather than failing at
the broker.

Also corrects the bundle example, which claimed to stop before the
control plane runs and has raised one for some time. A comment about what
something does not do is a comment nobody updates.
This commit is contained in:
2026-08-30 02:36:42 +02:00
parent ef0d96a1a8
commit bdc9c436b4
5 changed files with 57 additions and 13 deletions
+12 -8
View File
@@ -2,20 +2,24 @@
## `substrate-first-node.lock`
What a machine must be before a mesh exists — steps 0 to 4 of the bootstrap in
[novox/hq `07-the-substrate.md`](https://git.novox.be/novox/hq):
What a machine must be before a mesh exists — the bootstrap in
[novox/hq `07-the-substrate.md`](https://git.novox.be/novox/hq), whole:
```
0 a container runtime
1 the store runs
2 a database per context one today, `inventory`
3 that context's schema mesh-control migrate
4 the broker runs
2 a database per context `inventory` and `identity`
3 those contexts' schemas mesh-control migrate
4 the broker runs with a certificate it generated itself
5 the control plane runs mesh-control serve
```
**It stops there, and the file says why.** Step 5 is a virtual host, a credential and a
certificate; step 6 is the control plane running. Nothing consumes any of them yet, and a bundle
whose last step cannot be checked is worse than a shorter one.
**A machine that applies this is a mesh** — one node, with nothing joined to it yet, which is
exactly what the first node is (novox/hq ADR 0004). From here it hands out tokens and everything
else joins the ordinary way.
This file said it stopped at step 4 for longer than that was true, which is its own small lesson:
a comment about what something does not do is a comment nobody updates.
Build a host carrying it:
+4 -3
View File
@@ -1,9 +1,10 @@
// substrate-first-node.lock — what a machine must be before a mesh exists.
//
// Steps 0 to 5 of the bootstrap (novox/hq 03-DESIGN/01-to-be/07-the-substrate.md): a container
// runtime, a store, a database per context, that context's schema, and the broker.
// The whole bootstrap (novox/hq 03-DESIGN/01-to-be/07-the-substrate.md): a container runtime, a
// store, a database per context, those contexts' schemas, the broker, and the control plane
// running on top of them.
//
// It stops before step 6, where the control plane runs.
// It stopped before the control plane once, and this comment said so for longer than it was true.
//
// The broker generates its OWN certificate, in its own image, into a volume it then mounts read
// only. Self-signed, because at this moment there is no mesh to issue one and no public name to