A bed for the trust anchor, and the bundle rewrite its foundation needs
novox/hq ADR 0147. The bed dials the authority itself — step-ca serves its own API with a leaf it issued — so a plain client verifying that handshake is verifying one thing: the mesh's root is in this machine's trust store. The negative half runs twice, before the module is assigned and after it is unassigned; an anchor bed that only checks the success would pass on a machine that trusted everything. foundationBundle learns the new bundle's bus reference, the way it already knows the store's and the previous broker's. The bed does not run yet: raising a foundation fails before any module is reached (novox/hq issue 146).
This commit is contained in:
@@ -0,0 +1,40 @@
|
||||
# One machine that becomes a mesh, runs the mesh's own certificate authority, and is then given the
|
||||
# module that makes it trust it — the bed for novox/hq ADR 0147 and issue 129.
|
||||
#
|
||||
# The question is narrow and the bed is shaped to answer only it: does a machine holding `ca-trust`
|
||||
# verify a certificate from the mesh's own authority with no bundle argument and no `-k`, and does
|
||||
# it stop verifying it when the module is taken away? The authority itself is what is dialled —
|
||||
# step-ca serves its own API with a leaf it issued — so nothing else has to be right for the answer
|
||||
# to mean something. No proxy, no routed name, no public issuance: those are the certificates and
|
||||
# route-forwarding beds, and a trust bed that leaned on them would pass for their reasons.
|
||||
#
|
||||
# The negative half is not optional. It is asserted BEFORE the module is assigned and again AFTER it
|
||||
# is unassigned, because an anchor bed that only ever checks the success is one that would pass on a
|
||||
# machine that already trusted everything.
|
||||
#
|
||||
# MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
||||
# MESH_LAB_CATALOG=.../mesh-catalog/modules
|
||||
# step-ca's image is upstream and pinned by the catalogue; the machine pulls it over its uplink.
|
||||
# ca-trust carries no image at all — a script, a unit, and the machine's own systemd.
|
||||
scenario: trust-anchor
|
||||
|
||||
segments:
|
||||
hosting:
|
||||
kind: public
|
||||
cidr: [192.0.2.0/24]
|
||||
|
||||
machines:
|
||||
anchor:
|
||||
at: { segment: hosting, address: [192.0.2.10] }
|
||||
egress: true
|
||||
inbound: allow
|
||||
memory: 3GiB
|
||||
cpus: 2
|
||||
|
||||
images:
|
||||
- mesh-controller:development
|
||||
|
||||
place:
|
||||
# Only the host. The authority's image comes from the internet over the machine's uplink, and the
|
||||
# trust module has nothing to place.
|
||||
all: [host]
|
||||
Reference in New Issue
Block a user