A bed for the trust anchor, and the bundle rewrite its foundation needs #52

Merged
jschoubben merged 1 commits from feat/ca-trust into main 2026-09-29 14:06:39 +00:00
Owner

novox/hq ADR 0147.

The bed dials the authority itself — step-ca serves its own API with a leaf it issued — so a plain client verifying that handshake is verifying exactly one thing: the mesh's root is in this machine's trust store. No proxy, no routed name, no public issuance; a trust bed leaning on those would pass for their reasons.

The negative half runs twice, before the module is assigned and after it is unassigned. An anchor bed that only checked the success would pass on a machine that already trusted everything, and would say nothing at all about removal.

foundationBundle learns the new bundle's bus reference, the way it already knows the store's and the previous broker's — the new bundle is the first one a bed has tried to raise.

The bed does not run yet. Raising a foundation fails before any module is reached, in both bundles that exist (novox/hq issue 146).

novox/hq ADR 0147. The bed dials the authority itself — step-ca serves its own API with a leaf it issued — so a plain client verifying that handshake is verifying exactly one thing: the mesh's root is in this machine's trust store. No proxy, no routed name, no public issuance; a trust bed leaning on those would pass for their reasons. The negative half runs twice, before the module is assigned and after it is unassigned. An anchor bed that only checked the success would pass on a machine that already trusted everything, and would say nothing at all about removal. `foundationBundle` learns the new bundle's bus reference, the way it already knows the store's and the previous broker's — the new bundle is the first one a bed has tried to raise. **The bed does not run yet.** Raising a foundation fails before any module is reached, in both bundles that exist (novox/hq issue 146).
jschoubben added 1 commit 2026-09-29 13:28:22 +00:00
novox/hq ADR 0147. The bed dials the authority itself — step-ca serves its
own API with a leaf it issued — so a plain client verifying that handshake is
verifying one thing: the mesh's root is in this machine's trust store. The
negative half runs twice, before the module is assigned and after it is
unassigned; an anchor bed that only checks the success would pass on a machine
that trusted everything.

foundationBundle learns the new bundle's bus reference, the way it already
knows the store's and the previous broker's. The bed does not run yet: raising
a foundation fails before any module is reached (novox/hq issue 146).
jschoubben merged commit f94ee2dd0e into main 2026-09-29 14:06:39 +00:00
jschoubben deleted branch feat/ca-trust 2026-09-29 14:06:39 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-lab#52