Files
alkvault/docs/architecture/questions/021-remote-vault-administration.md
T
glm-5.2 110146870a Rebrand alknet-vault -> alkvault
Rename the crate from alknet-vault to alkvault across source and docs:
- Cargo.toml: package name and lib name (alknet_vault -> alkvault)
- src/ doc comments and doc-test use statements
- tests/ use statements and one string literal

Convert references to non-vault alknet ADRs (003, 005, 008, 010, 014,
064) that were broken local links into @alkdev/alknet: cross-repo
references, matching the alktype sibling pattern. Local ADR/OQ
references are now proper links. Rewrote monorepo path references
(crates/alknet-vault/src/...) to the flat layout (src/...). Fixed
sdd_process.md package name (@alkdev/storage -> @alkdev/alkvault).

ADR/OQ renumbering is deferred to a subsequent pass per the alknet-
origin numbering convention. Generic prose 'vault' and type names
(VaultServiceHandle, VaultServiceError, etc.) are unchanged.

Build, 108 tests, and clippy all pass clean.
2026-08-02 09:25:43 +00:00

2.1 KiB

OQ-21: Remote Vault Administration

  • Origin: service.md, protocol.md, ADR-019

  • Status: resolved

  • Door type: One-way (vault crate is local-only by construction)

  • Priority: medium

  • Resolution: Remote vault access is not a feature of the vault crate. ADR-025 dropped irpc from the vault, making the vault local-only by construction — no RemoteService trait, no wire format for vault messages, no default-insecure remote handler. The vault's API is VaultServiceHandle (direct method calls), nothing else.

    If remote vault access is ever needed (e.g., the machine→worker pattern), it requires a separate vault-server crate that depends on both alknet-core (for IdentityProvider, scopes, auth-wrapping) and alkvault (for VaultServiceHandle). That crate would define its own threat model, access policy, operation filtering (Unlock/Lock local-only), and wire format — and requires its own ADR. This is a deliberate addition, not a flag flip on a default that was already loaded.

    The pre-ADR-025 deferral framed remote access as "non-breaking" (the wire format was additive). That framing was misleading: once workers build dependencies on the remote vault API, disabling it breaks them — the door is operationally one-way even if the wire format is additive. ADR-025 inverts the default: the vault is local-only by construction, and remote access requires building something new, not removing a default.

    Per-node vaults are the recommended pattern for multi-node deployments: each node has its own vault and mnemonic; credentials are encrypted for the receiving node's public key, not decrypted centrally. This is end-to-end encryption between nodes, matching ADR-008's "capability source" model.

  • Cross-references: @alkdev/alknet: ADR-005, @alkdev/alknet: ADR-008, @alkdev/alknet: ADR-014, ADR-018, ADR-019, ADR-025, protocol.md, service.md