novox/hq ADR 0147. The bed dials the authority itself — step-ca serves its own API with a leaf it issued — so a plain client verifying that handshake is verifying one thing: the mesh's root is in this machine's trust store. The negative half runs twice, before the module is assigned and after it is unassigned; an anchor bed that only checks the success would pass on a machine that trusted everything. foundationBundle learns the new bundle's bus reference, the way it already knows the store's and the previous broker's. The bed does not run yet: raising a foundation fails before any module is reached (novox/hq issue 146).
41 lines
1.7 KiB
YAML
41 lines
1.7 KiB
YAML
# One machine that becomes a mesh, runs the mesh's own certificate authority, and is then given the
|
|
# module that makes it trust it — the bed for novox/hq ADR 0147 and issue 129.
|
|
#
|
|
# The question is narrow and the bed is shaped to answer only it: does a machine holding `ca-trust`
|
|
# verify a certificate from the mesh's own authority with no bundle argument and no `-k`, and does
|
|
# it stop verifying it when the module is taken away? The authority itself is what is dialled —
|
|
# step-ca serves its own API with a leaf it issued — so nothing else has to be right for the answer
|
|
# to mean something. No proxy, no routed name, no public issuance: those are the certificates and
|
|
# route-forwarding beds, and a trust bed that leaned on them would pass for their reasons.
|
|
#
|
|
# The negative half is not optional. It is asserted BEFORE the module is assigned and again AFTER it
|
|
# is unassigned, because an anchor bed that only ever checks the success is one that would pass on a
|
|
# machine that already trusted everything.
|
|
#
|
|
# MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/foundation-first-node.lock
|
|
# MESH_LAB_CATALOG=.../mesh-catalog/modules
|
|
# step-ca's image is upstream and pinned by the catalogue; the machine pulls it over its uplink.
|
|
# ca-trust carries no image at all — a script, a unit, and the machine's own systemd.
|
|
scenario: trust-anchor
|
|
|
|
segments:
|
|
hosting:
|
|
kind: public
|
|
cidr: [192.0.2.0/24]
|
|
|
|
machines:
|
|
anchor:
|
|
at: { segment: hosting, address: [192.0.2.10] }
|
|
egress: true
|
|
inbound: allow
|
|
memory: 3GiB
|
|
cpus: 2
|
|
|
|
images:
|
|
- mesh-controller:development
|
|
|
|
place:
|
|
# Only the host. The authority's image comes from the internet over the machine's uplink, and the
|
|
# trust module has nothing to place.
|
|
all: [host]
|