Files
mesh-lab/test/integration
jschoubben 99b3444b19 Two machines, one mesh, a credential neither end had to be told twice
Everything before this proved a part. This proves the parts meet, which
the project keeps saying cannot be checked any other way.

A bare machine applies the substrate bundle and becomes a mesh — store,
schemas, broker with a certificate it generated itself, control plane
serving. Both machines then join it with nothing but a token. A database
is declared on one and an application on the other, and after a push:

- both ends hold the SAME password, or nothing could authenticate
- it is mode 0600 on the machine that uses it
- it appears in neither machine's stored declaration, neither machine's
  reported state, nor the control plane's database — so it was not
  readable by the broker that carried it or the mesh that sent it
- the consumer is also told where its database is, by a name the mesh
  wrote into that machine's hosts file

The bundle's image references are rewritten to the ones this scenario's
registry serves. A digest belongs to whatever registry serves it, so a
committed bundle names a registry that is not this one — rewriting is
what makes it applicable rather than a placeholder to tidy away.

Two faults found getting here, both fixed in mesh-host: `apply` could not
read a file the bundle could, and the token did not say what the mesh
calls the machine.
2026-08-30 03:05:07 +02:00
..