Files
mesh-lab/scenarios/vault-node.yml
T
jschoubben 639175ec4a A bed for the vault: redis's password as a secret it provides, rotated
Design 13's three logins, for a secret that had no owner before (novox/hq
ADR 0085): the delivered password authenticates against the real redis, the
one `rotate secret` delivers authenticates, and the one rotated away is
refused. Plus the owner's half: the vault's ledger names the holder and the
fingerprint, notices the rotation, and answers over the mesh by fingerprint,
never by value. Runs the catalogue's own manifests.
2026-09-21 00:01:50 +02:00

33 lines
1.1 KiB
YAML

# One machine that becomes a mesh and then assigns itself mesh-vault and redis — a provider whose own
# password is a `secret` the vault provides (novox/hq ADR 0085, design 24).
#
# redis-node proves a provider's runtime. This proves the vault: redis requires `secret`, the mesh
# mints the pair credential, the host fills redis.conf from it, redis authenticates with it, and the
# vault's ledger records its fingerprint. Then `rotate secret` moves both ends: the new password
# works, the old one is refused, and the vault says it was rotated — design 13's three logins, for a
# secret that had no owner before.
scenario: vault-node
segments:
hosting:
kind: public
cidr: [192.0.2.0/24]
machines:
anchor:
at: { segment: hosting, address: [192.0.2.10] }
egress: true
inbound: allow
memory: 3GiB
cpus: 2
images:
- mesh-controller:development
# Built by scripts/build-module-runtime.sh mesh-vault / redis into the local daemon; the machine holds
# each by its own image ID. redis's server image is pulled upstream by digest.
- mesh-runtime-mesh-vault:development
- mesh-runtime-redis:development
place:
all: [host, runtime]