Beds for the vault and for genesis's root secrets #39

Merged
jschoubben merged 5 commits from feat/secrets-vault into main 2026-09-21 08:03:22 +00:00
5 Commits
Author SHA1 Message Date
jschoubben 7fad006e56 A push that said 'told' is a push that sent, whatever became of the exec afterwards 2026-09-21 01:47:26 +02:00
jschoubben fb72db73bc The vault bed recovers redis's vault-provided secret from the export 2026-09-21 00:36:16 +02:00
jschoubben 960fa3607f The genesis bed waits for the node to settle before asking it anything
Applying the packet filter restarts the container runtime a few seconds
after the installer's last push returns; a command racing that window dies
with 'No such exec instance'. Wait for the node to report applied and
current, and retry that error like the recreate it is.
2026-09-21 00:33:23 +02:00
jschoubben 9da2d01ca0 The genesis bed checks the root secrets: made, sealed to the operator key, recoverable
V5: the template's password is refused by the store, the operator key and the
export sit beside the bundle at 0600, the vault keeps the export, and a person
with the key recovers the superuser off the mesh and opens the store with it.
V2 dials the broker with the administrator password genesis made.
2026-09-21 00:12:55 +02:00
jschoubben 639175ec4a A bed for the vault: redis's password as a secret it provides, rotated
Design 13's three logins, for a secret that had no owner before (novox/hq
ADR 0085): the delivered password authenticates against the real redis, the
one `rotate secret` delivers authenticates, and the one rotated away is
refused. Plus the owner's half: the vault's ledger names the holder and the
fingerprint, notices the rotation, and answers over the mesh by fingerprint,
never by value. Runs the catalogue's own manifests.
2026-09-21 00:01:50 +02:00