Remove the inert MESH_SEAL_KEY, and cite the ADR that retired it correctly

ADR 0048 (2026-09-05) settled that a provider is handed the credential the mesh minted —
sealed to the provider node, unsealed by the host into a 0600 file — and removed the
symmetric seal from the SDK entirely; hq issue 032 records it resolved. The lab-only
MESH_SEAL_KEY injections were tombstones read by nothing: two-node-db went green on the
superuser delivery, not the seal key. Removed, and provider-uses-mesh-credential's
citations corrected from ADR 0053 (a scheduled step) to ADR 0048.

https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
This commit is contained in:
2026-09-17 22:02:31 +02:00
parent 1e4713c311
commit 2438883a5f
2 changed files with 5 additions and 11 deletions
@@ -1,5 +1,5 @@
/**
* A provider creates the resource with the credential the mesh minted — novox/hq ADR 0053.
* A provider creates the resource with the credential the mesh minted — novox/hq ADR 0048.
*
* The old provisioner generated its own password, sealed it with a key nothing delivered, and
* handed it back. This proves the corrected contract: redis's provisioner reads the mesh's
@@ -142,7 +142,7 @@ test("redis creates a consumer's login with the password the mesh minted, sealin
}, async () => {
// redis as a provider: the server, and a broker-bound runtime that serves its tools AND runs its
// provisioner. The provisioner is pointed at the contributions file the mesh would write
// (MESH_RECEIVES). There is NO MESH_SEAL_KEY — the whole point of ADR 0053 is that a provider
// (MESH_RECEIVES). There is NO MESH_SEAL_KEY — the whole point of ADR 0048 is that a provider
// needs none.
const manifest = JSON.stringify({
module: "redis",
@@ -228,7 +228,7 @@ test("redis creates a consumer's login with the password the mesh minted, sealin
// And it needed no seal key: the runtime came up and provisioned with MESH_SEAL_KEY set nowhere.
const env = await must(`docker inspect mesh-redis --format '{{json .Config.Env}}'`);
assert.doesNotMatch(env, /MESH_SEAL_KEY/, `a seal key was set after all — ADR 0053 is not what ran:\n${env}`);
assert.doesNotMatch(env, /MESH_SEAL_KEY/, `a seal key was set after all — ADR 0048 is not what ran:\n${env}`);
// The provisioner emitted its lifecycle event under the bound account, and no emit was refused.
const log = (await on(`docker logs mesh-redis 2>&1`)).out;