Retire provider-uses-mesh-credential: the grant end-to-end bed proves it against the catalogue's redis, with the mesh writing the contributions; its no-seal-key assertion moves there (issue 074)

This commit is contained in:
2026-09-21 23:35:01 +02:00
parent 0d8eac88c3
commit fd1e5499d0
3 changed files with 8 additions and 236 deletions
@@ -220,4 +220,11 @@ test("the mesh grants a consumer redis's cache, and the credential it delivers a
assert.doesNotMatch(authed.out, /WRONGPASS|NOPERM|no password/i,
`the consumer's mesh-delivered credential did not authenticate — the two ends do not agree:\n${authed.out}`);
assert.match(authed.out, /PONG/, `expected PONG authenticating as the granted consumer:\n${authed.out}`);
// And the provider needed no seal key to do it: the password reached it as a file the host left
// after unsealing, so MESH_SEAL_KEY is set nowhere (novox/hq ADR 0048). Carried over from the
// retired provider-uses-mesh-credential bed, whose other proofs this bed makes with the mesh
// writing the contributions rather than the bed.
const runtimeEnv = await must(`docker inspect mesh-redis --format '{{json .Config.Env}}'`);
assert.doesNotMatch(runtimeEnv, /MESH_SEAL_KEY/, `a seal key was set after all — ADR 0048 is not what ran:\n${runtimeEnv}`);
});