Beds issue only modules with a broker secret: an own secret is minted at resolve
This commit is contained in:
@@ -188,7 +188,6 @@ test("the mesh routes a public name through the proxy to the consumer, and withd
|
||||
for (const name of ["step-ca", "route-proxy", "hello-web"]) {
|
||||
await must(`printf %s ${quote(catalogueModule(name, held))} > /tmp/${name}.json && docker cp /tmp/${name}.json mesh-controller:/${name}.json`);
|
||||
await mesh(`module add /${name}.json`);
|
||||
if (name === "step-ca") await mesh(`module issue ${name} --node ${MACHINE}`);
|
||||
await mesh(`assign ${MACHINE} ${name}`);
|
||||
}
|
||||
|
||||
|
||||
@@ -800,9 +800,10 @@ test("the full mesh forms across the access point and both server sets converge"
|
||||
for (const { name } of mods) {
|
||||
try {
|
||||
const broker = await ensureAdded(name);
|
||||
// Issued when the module holds a broker account or an own-secret the mesh mints for it
|
||||
// (step-ca's password, ADR 0098); a requirement kept in the vault needs no issue.
|
||||
if (broker || loadManifest(name).manifest.includes('"own-secrets"')) await mesh(`module issue ${name} --node ${node}`);
|
||||
// Issued only when the module holds a broker account: an own secret the mesh mints
|
||||
// (step-ca's password) is minted at resolve, and `module issue` refuses a module with no
|
||||
// broker secret to deliver into (issue 078).
|
||||
if (broker) await mesh(`module issue ${name} --node ${node}`);
|
||||
await mesh(`assign ${node} ${name}`);
|
||||
assigned[node]!.add(name);
|
||||
} catch (err) {
|
||||
|
||||
Reference in New Issue
Block a user