packages/headless on the vault-adapter seam #51
Labels
No labels
area:docs
area:identity
area:ops
area:plugin
area:server
channel:community
channel:direct
channel:owned
channel:press
channel:social
e2ee-constrained
gate:at-ga
gate:pre-ga
marketing
parity
relay:absent
relay:planned
relay:requested
relay:supported
risk:additive
risk:contract
risk:none
usability
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
Nectenda/nectenda#51
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Part of #37. Enables the Git mirror and the document API — build once, close three.
What Relay does
Not shipped. Headless sync is their issue #74; the maintainer says they are
"experimenting with, but haven't yet committed to on our roadmap". Their Git sync
works differently — see that issue.
Why ours must be shaped differently
Relay runs
relay-git-syncas a server-side service that subscribes overwebsocket, because their server can read plaintext. Ours cannot: the server
holds no keys and would hand out ciphertext under HMAC'd names.
So a headless Nectenda client must run where the keys are — the customer's
own machine or their own infrastructure. That is a different shape and arguably a
better one, and it should be explained rather than apologised for.
Why it is cheaper than it looks
packages/plugin/src/vault-adapter.tsis already a narrow, Obsidian-freeinterface with an in-memory
FakeVaultbehind it. A NodeFsVaultimplementingthe same interface, plus the existing multiplexed provider, folder crypto and a
device identity, is a headless sync client.
The genuinely new decision
How an unattended process holds a passphrase. That is a
docs/security-model.mdquestion before it is a code one, and it must beanswered there first. The current model — key cached in the OS credential store,
passphrase never leaving the device — does not obviously extend to a daemon.
Risk
risk:additive. A new package; the server is unchanged.Verification
A headless client and a real Obsidian vault converge on the same folder, proven
in the e2e suite rather than by inspection.
Moved to the Vikunja board as NEC-28: https://projectron.nerchure.com/tasks/28