runtime: connect with a sealed, scoped credential over pinned amqps (ADR 0048) #2

Closed
jschoubben wants to merge 2 commits from events/module-credential into events/adr-0047-alignment
Owner

Implements ADR 0048's runtime half.

  • Reads MESH_BROKER_FILE — the sealed {url,fingerprint,node,module} the mesh delivered — and connects over amqps pinned to exactly that certificate, two-phase (fetch cert, verify fingerprint, then trust only it) because Node's checkServerIdentity doesn't run under rejectUnauthorized:false, so a naive connect-then-check would leak the password to an impostor.
  • A scoped module (assumeExchanges) never declares the exchanges nor its dead-lettered queue (its account may not) — the mesh pre-declared them, so it passively checkQueues, binds, consumes.
  • The RPC reply queue is lazy, and a module registering no tools serves none — a pure-events consumer touches only what its account allows.
  • Identity (node/module) comes from the credential, so no manifest need interpolate a node.

Verified end-to-end against a real broker as the scoped account, and in the lab (assigned audit-logger, 1/1).

Stacked on events/adr-0047-alignment (the ADR 0047 wire alignment, PR #1).

https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF

Implements ADR 0048's runtime half. - Reads `MESH_BROKER_FILE` — the sealed `{url,fingerprint,node,module}` the mesh delivered — and connects over **amqps pinned to exactly that certificate**, two-phase (fetch cert, verify fingerprint, then trust only it) because Node's `checkServerIdentity` doesn't run under `rejectUnauthorized:false`, so a naive connect-then-check would leak the password to an impostor. - A scoped module (`assumeExchanges`) never declares the exchanges nor its dead-lettered queue (its account may not) — the mesh pre-declared them, so it passively `checkQueue`s, binds, consumes. - The RPC reply queue is lazy, and a module registering no tools serves none — a pure-events consumer touches only what its account allows. - Identity (node/module) comes from the credential, so no manifest need interpolate a node. Verified end-to-end against a real broker as the scoped account, and in the lab (assigned audit-logger, 1/1). Stacked on `events/adr-0047-alignment` (the ADR 0047 wire alignment, PR #1). https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
jschoubben added 2 commits 2026-09-04 00:13:40 +00:00
A module reads its broker credential from MESH_BROKER_FILE — the sealed
{url,fingerprint} the mesh delivered — and connects over amqps pinned to
exactly that certificate. The pin is two-phase (fetch cert, verify, then
trust only it), because Node's checkServerIdentity does not run under
rejectUnauthorized:false, so a naive connect-then-check would already have
sent the password to whoever answered.

A scoped module (assumeExchanges) never declares the exchanges (its account
may not) nor its own queue with a dead-letter (the broker refuses that to a
non-administrator) — the mesh pre-declared the queue, so it passively checks
it, binds and consumes. The RPC reply queue is lazy, and a module that
registered no tools serves none: a pure-events consumer touches only what its
account allows.

Verified end-to-end against a real broker as the scoped account: the audit
logger consumes # and records events, over an account that is not the
broker's own.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
The mesh scoped the account to a node and module; the credential now carries
both, so the runtime names its queue and stamps its events as the mesh
authorised without a manifest interpolating a node the vocabulary has no token
for. Verified: with only MESH_BROKER_FILE, the audit logger consumed as
anchor/audit-logger.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
jschoubben closed this pull request 2026-09-05 01:19:15 +00:00

Pull request closed

This pull request cannot be reopened because the branch was deleted.
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-tools#2