From fb72db73bc674946d885a0e2a7ef895b0b4cccdc Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 21 Sep 2026 00:36:16 +0200 Subject: [PATCH] The vault bed recovers redis's vault-provided secret from the export --- test/integration/assigned-vault.test.ts | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/test/integration/assigned-vault.test.ts b/test/integration/assigned-vault.test.ts index 918cd7d..1059194 100644 --- a/test/integration/assigned-vault.test.ts +++ b/test/integration/assigned-vault.test.ts @@ -414,6 +414,17 @@ test("the operator recovers a root secret with a key the mesh never held, from t assert.equal(wrong.ok, false, `a different operator key opened the secret:\n${wrong.out}`); assert.match(wrong.out, /does not open it/, wrong.out); + // 3b. And the secret the vault PROVIDES — redis's password, a pair credential — is recoverable + // the same way, off the mesh: the export names it by the consumer and the provision. + const redisPassword = (await must(`cat ${SECRET_FILE}`)).replace(/\n$/, ""); + const pairLine = doc.kept.find((k) => k.module === "redis" && k.name === "secret"); + assert.ok(pairLine, `redis's vault-provided secret is not in the export:\n${exported}`); + await must(`cp ${ROOT}/export.json ${OPERATOR_DIR}/export.json && chmod 644 ${OPERATOR_DIR}/export.json`); + await operator(`secret recover ${MACHINE} redis secret --key /work/operator.key --from-export /work/export.json --out /work/redis.secret`); + const recoveredRedis = (await must(`cat ${OPERATOR_DIR}/redis.secret`)).replace(/\n$/, ""); + assert.equal(recoveredRedis, redisPassword, "the recovered pair credential is not the password redis runs with"); + assert.equal(await pingAs(recoveredRedis), "PONG", "the recovered password does not open redis"); + // 4. The vault serves the export over the mesh — ciphertext, plus what is NOT recoverable. const served = await vaultTool("secret_export", { sealed: false }); assert.equal(served["available"], true, JSON.stringify(served));