Design 13's three logins, for a secret that had no owner before (novox/hq ADR 0085): the delivered password authenticates against the real redis, the one `rotate secret` delivers authenticates, and the one rotated away is refused. Plus the owner's half: the vault's ledger names the holder and the fingerprint, notices the rotation, and answers over the mesh by fingerprint, never by value. Runs the catalogue's own manifests.
33 lines
1.1 KiB
YAML
33 lines
1.1 KiB
YAML
# One machine that becomes a mesh and then assigns itself mesh-vault and redis — a provider whose own
|
|
# password is a `secret` the vault provides (novox/hq ADR 0085, design 24).
|
|
#
|
|
# redis-node proves a provider's runtime. This proves the vault: redis requires `secret`, the mesh
|
|
# mints the pair credential, the host fills redis.conf from it, redis authenticates with it, and the
|
|
# vault's ledger records its fingerprint. Then `rotate secret` moves both ends: the new password
|
|
# works, the old one is refused, and the vault says it was rotated — design 13's three logins, for a
|
|
# secret that had no owner before.
|
|
scenario: vault-node
|
|
|
|
segments:
|
|
hosting:
|
|
kind: public
|
|
cidr: [192.0.2.0/24]
|
|
|
|
machines:
|
|
anchor:
|
|
at: { segment: hosting, address: [192.0.2.10] }
|
|
egress: true
|
|
inbound: allow
|
|
memory: 3GiB
|
|
cpus: 2
|
|
|
|
images:
|
|
- mesh-controller:development
|
|
# Built by scripts/build-module-runtime.sh mesh-vault / redis into the local daemon; the machine holds
|
|
# each by its own image ID. redis's server image is pulled upstream by digest.
|
|
- mesh-runtime-mesh-vault:development
|
|
- mesh-runtime-redis:development
|
|
|
|
place:
|
|
all: [host, runtime]
|