# One machine that becomes a mesh and then assigns itself mesh-vault and redis — a provider whose own # password is a `secret` the vault provides (novox/hq ADR 0085, design 24). # # redis-node proves a provider's runtime. This proves the vault: redis requires `secret`, the mesh # mints the pair credential, the host fills redis.conf from it, redis authenticates with it, and the # vault's ledger records its fingerprint. Then `rotate secret` moves both ends: the new password # works, the old one is refused, and the vault says it was rotated — design 13's three logins, for a # secret that had no owner before. scenario: vault-node segments: hosting: kind: public cidr: [192.0.2.0/24] machines: anchor: at: { segment: hosting, address: [192.0.2.10] } egress: true inbound: allow memory: 3GiB cpus: 2 images: - mesh-controller:development # Built by scripts/build-module-runtime.sh mesh-vault / redis into the local daemon; the machine holds # each by its own image ID. redis's server image is pulled upstream by digest. - mesh-runtime-mesh-vault:development - mesh-runtime-redis:development place: all: [host, runtime]