Remove the inert MESH_SEAL_KEY, and cite the ADR that retired it correctly

ADR 0048 (2026-09-05) settled that a provider is handed the credential the mesh minted —
sealed to the provider node, unsealed by the host into a 0600 file — and removed the
symmetric seal from the SDK entirely; hq issue 032 records it resolved. The lab-only
MESH_SEAL_KEY injections were tombstones read by nothing: two-node-db went green on the
superuser delivery, not the seal key. Removed, and provider-uses-mesh-credential's
citations corrected from ADR 0053 (a scheduled step) to ADR 0048.

https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
2026-09-17 22:02:31 +02:00
parent 1e4713c311
commit 2438883a5f
2 changed files with 5 additions and 11 deletions
@@ -209,8 +209,8 @@ test("consumers on a joined node get their databases from the one foundation sto
// they land on changes.
// ================================================================================================
// --- redis: a cache provider on the host network (127.0.0.1:6379), MESH_SEAL_KEY set lab-locally
// because the mesh cannot yet deliver a seal key to a provider's runtime (04-ISSUES). It carries
// --- redis: a cache provider on the host network (127.0.0.1:6379). No seal key: the provider
// is handed the minted credential already unsealed by the host (ADR 0048). It carries
// the committed provides/serves/receives/grants so baserow's redis-cache requirement resolves. ----
const redisManifest = JSON.stringify({
module: "redis",
@@ -253,7 +253,6 @@ test("consumers on a joined node get their databases from the one foundation sto
GRANTS: "/var/lib/redis-module/grants",
MESH_PROVISION_REDIS: "127.0.0.1:6379",
MESH_PROVISION_PASSWORD_FILE: "/run/secrets/default",
MESH_SEAL_KEY: "lab-only-seal-key",
},
},
],
@@ -373,11 +372,6 @@ test("consumers on a joined node get their databases from the one foundation sto
r.image = pinned(`mesh-runtime-${name}@sha256:${"0".repeat(64)}`);
delete r.artifact;
}
// The provisioner runtime seals a consumer's credential; the mesh cannot yet deliver a seal
// key to a provider's runtime, so set it lab-locally — the same workaround the redis provider
// uses here (hq 04-ISSUES/022, the open provider-seal-key work).
const env = (r as { env?: Record<string, string> }).env;
if (env && typeof env["MESH_RECEIVES"] === "string") env["MESH_SEAL_KEY"] = "lab-only-seal-key";
}
const manifest = JSON.stringify(m);
return { manifest, broker: manifest.includes("MESH_BROKER_FILE") };