Prove rotation against a real database, with a real login

Two ends holding a matching string proves they agree, not that either is right.
So the check is three logins over the private network from the consumer's own
machine: the delivered credential works, the rotated one works, and the one
that was rotated away does not. Without the last, the test passes against a
provider that added a password without replacing one.

Not over loopback: pg_hba trusts anything there, and a deliberately wrong
password returned a row for a whole afternoon once.
This commit is contained in:
2026-08-31 02:39:00 +02:00
parent f5619b02d6
commit 21a1e85d32
2 changed files with 99 additions and 0 deletions
+3
View File
@@ -31,6 +31,9 @@ images:
# And the builder, because it is a module the mesh assigns rather than a program somebody
# starts by hand — which is the only way its credential can be one the mesh delivered.
- mesh-builder:development
# And the provisioner, which is what makes a sealed credential true on a machine — the mesh
# discarded the plaintext and cannot tell a database to start accepting it.
- mesh-provision-postgres:development
place:
all: [host, runtime]