Remove the inert MESH_SEAL_KEY; cite ADR 0048 correctly #30

Merged
jschoubben merged 1 commits from cleanup/seal-key-tombstones into main 2026-09-17 20:02:45 +00:00
2 changed files with 5 additions and 11 deletions
@@ -209,8 +209,8 @@ test("consumers on a joined node get their databases from the one foundation sto
// they land on changes. // they land on changes.
// ================================================================================================ // ================================================================================================
// --- redis: a cache provider on the host network (127.0.0.1:6379), MESH_SEAL_KEY set lab-locally // --- redis: a cache provider on the host network (127.0.0.1:6379). No seal key: the provider
// because the mesh cannot yet deliver a seal key to a provider's runtime (04-ISSUES). It carries // is handed the minted credential already unsealed by the host (ADR 0048). It carries
// the committed provides/serves/receives/grants so baserow's redis-cache requirement resolves. ---- // the committed provides/serves/receives/grants so baserow's redis-cache requirement resolves. ----
const redisManifest = JSON.stringify({ const redisManifest = JSON.stringify({
module: "redis", module: "redis",
@@ -253,7 +253,6 @@ test("consumers on a joined node get their databases from the one foundation sto
GRANTS: "/var/lib/redis-module/grants", GRANTS: "/var/lib/redis-module/grants",
MESH_PROVISION_REDIS: "127.0.0.1:6379", MESH_PROVISION_REDIS: "127.0.0.1:6379",
MESH_PROVISION_PASSWORD_FILE: "/run/secrets/default", MESH_PROVISION_PASSWORD_FILE: "/run/secrets/default",
MESH_SEAL_KEY: "lab-only-seal-key",
}, },
}, },
], ],
@@ -373,11 +372,6 @@ test("consumers on a joined node get their databases from the one foundation sto
r.image = pinned(`mesh-runtime-${name}@sha256:${"0".repeat(64)}`); r.image = pinned(`mesh-runtime-${name}@sha256:${"0".repeat(64)}`);
delete r.artifact; delete r.artifact;
} }
// The provisioner runtime seals a consumer's credential; the mesh cannot yet deliver a seal
// key to a provider's runtime, so set it lab-locally — the same workaround the redis provider
// uses here (hq 04-ISSUES/022, the open provider-seal-key work).
const env = (r as { env?: Record<string, string> }).env;
if (env && typeof env["MESH_RECEIVES"] === "string") env["MESH_SEAL_KEY"] = "lab-only-seal-key";
} }
const manifest = JSON.stringify(m); const manifest = JSON.stringify(m);
return { manifest, broker: manifest.includes("MESH_BROKER_FILE") }; return { manifest, broker: manifest.includes("MESH_BROKER_FILE") };
@@ -1,5 +1,5 @@
/** /**
* A provider creates the resource with the credential the mesh minted — novox/hq ADR 0053. * A provider creates the resource with the credential the mesh minted — novox/hq ADR 0048.
* *
* The old provisioner generated its own password, sealed it with a key nothing delivered, and * The old provisioner generated its own password, sealed it with a key nothing delivered, and
* handed it back. This proves the corrected contract: redis's provisioner reads the mesh's * handed it back. This proves the corrected contract: redis's provisioner reads the mesh's
@@ -142,7 +142,7 @@ test("redis creates a consumer's login with the password the mesh minted, sealin
}, async () => { }, async () => {
// redis as a provider: the server, and a broker-bound runtime that serves its tools AND runs its // redis as a provider: the server, and a broker-bound runtime that serves its tools AND runs its
// provisioner. The provisioner is pointed at the contributions file the mesh would write // provisioner. The provisioner is pointed at the contributions file the mesh would write
// (MESH_RECEIVES). There is NO MESH_SEAL_KEY — the whole point of ADR 0053 is that a provider // (MESH_RECEIVES). There is NO MESH_SEAL_KEY — the whole point of ADR 0048 is that a provider
// needs none. // needs none.
const manifest = JSON.stringify({ const manifest = JSON.stringify({
module: "redis", module: "redis",
@@ -228,7 +228,7 @@ test("redis creates a consumer's login with the password the mesh minted, sealin
// And it needed no seal key: the runtime came up and provisioned with MESH_SEAL_KEY set nowhere. // And it needed no seal key: the runtime came up and provisioned with MESH_SEAL_KEY set nowhere.
const env = await must(`docker inspect mesh-redis --format '{{json .Config.Env}}'`); const env = await must(`docker inspect mesh-redis --format '{{json .Config.Env}}'`);
assert.doesNotMatch(env, /MESH_SEAL_KEY/, `a seal key was set after all — ADR 0053 is not what ran:\n${env}`); assert.doesNotMatch(env, /MESH_SEAL_KEY/, `a seal key was set after all — ADR 0048 is not what ran:\n${env}`);
// The provisioner emitted its lifecycle event under the bound account, and no emit was refused. // The provisioner emitted its lifecycle event under the bound account, and no emit was refused.
const log = (await on(`docker logs mesh-redis 2>&1`)).out; const log = (await on(`docker logs mesh-redis 2>&1`)).out;