Beds for the vault and for genesis's root secrets #39

Merged
jschoubben merged 5 commits from feat/secrets-vault into main 2026-09-21 08:03:22 +00:00
Showing only changes of commit fb72db73bc - Show all commits
+11
View File
@@ -414,6 +414,17 @@ test("the operator recovers a root secret with a key the mesh never held, from t
assert.equal(wrong.ok, false, `a different operator key opened the secret:\n${wrong.out}`);
assert.match(wrong.out, /does not open it/, wrong.out);
// 3b. And the secret the vault PROVIDES — redis's password, a pair credential — is recoverable
// the same way, off the mesh: the export names it by the consumer and the provision.
const redisPassword = (await must(`cat ${SECRET_FILE}`)).replace(/\n$/, "");
const pairLine = doc.kept.find((k) => k.module === "redis" && k.name === "secret");
assert.ok(pairLine, `redis's vault-provided secret is not in the export:\n${exported}`);
await must(`cp ${ROOT}/export.json ${OPERATOR_DIR}/export.json && chmod 644 ${OPERATOR_DIR}/export.json`);
await operator(`secret recover ${MACHINE} redis secret --key /work/operator.key --from-export /work/export.json --out /work/redis.secret`);
const recoveredRedis = (await must(`cat ${OPERATOR_DIR}/redis.secret`)).replace(/\n$/, "");
assert.equal(recoveredRedis, redisPassword, "the recovered pair credential is not the password redis runs with");
assert.equal(await pingAs(recoveredRedis), "PONG", "the recovered password does not open redis");
// 4. The vault serves the export over the mesh — ciphertext, plus what is NOT recoverable.
const served = await vaultTool("secret_export", { sealed: false });
assert.equal(served["available"], true, JSON.stringify(served));