A bed for the trust anchor, and the bundle rewrite its foundation needs

novox/hq ADR 0147. The bed dials the authority itself — step-ca serves its
own API with a leaf it issued — so a plain client verifying that handshake is
verifying one thing: the mesh's root is in this machine's trust store. The
negative half runs twice, before the module is assigned and after it is
unassigned; an anchor bed that only checks the success would pass on a machine
that trusted everything.

foundationBundle learns the new bundle's bus reference, the way it already
knows the store's and the previous broker's. The bed does not run yet: raising
a foundation fails before any module is reached (novox/hq issue 146).
This commit is contained in:
2026-09-29 15:26:05 +02:00
parent 08e3aa04e7
commit 62a02d7e94
3 changed files with 270 additions and 0 deletions
+9
View File
@@ -40,6 +40,14 @@ const UPSTREAM_STORE =
"postgres@sha256:7456ef82e5f5bc43d997f4781bbd7c0d6389bff397564649a356e206ba473aee";
const UPSTREAM_BROKER =
"cloudamqp/lavinmq@sha256:3eb54c12916d700a978c2ea86e6362cd4974b0e3189508718006d4e6d341246b";
/**
* And the bus, for `foundation-first-node-nats.lock` — the bundle the mesh raises since it stopped
* speaking AMQP (novox/hq ADR 0131). The digest is the bundle's own: what the registry served was a
* copy of the upstream image, so the same digest resolves on Docker Hub, and this is a prefix being
* removed rather than a reference being replaced.
*/
const UPSTREAM_BUS =
"nats@sha256:b83efabe3e7def1e0a4a31ec6e078999bb17c80363f881df35edc70fcb6bb927";
/**
* The foundation bundle as a machine should receive it.
@@ -53,6 +61,7 @@ export function foundationBundle(path: string, held: HeldImage[]): string {
text = text.replaceAll(/[A-Za-z0-9_.:-]+\/postgres@sha256:[0-9a-f]{64}/g, UPSTREAM_STORE);
text = text.replaceAll(
/[A-Za-z0-9_.:-]+\/cloudamqp\/lavinmq@sha256:[0-9a-f]{64}/g, UPSTREAM_BROKER);
text = text.replaceAll(/[A-Za-z0-9_.:-]+:[0-9]+\/nats@sha256:[0-9a-f]{64}/g, UPSTREAM_BUS);
return pinnedInto(text, held);
}