ADR-016: Passphrase and readiness follow Holo’s module
- Status: Accepted
- Date: 2026-08-28
- Source: #15, issue description, section “6. Decisions (ADR amendments, effective now)”; summarised in #1 under “Amendments from the research record”
Context
From #15, section 5:
Holo-Host/holo-host
nix/modules/nixos/holochain/default.nix(pushed 2026-07-03): options underholo.holochain, default package holonix 0.5 (behind),passphraseFilegenerated withpwgeninpreStart,holochain --piped --config-path … < passphrase,Type = "notify"(the conductor doessd_notify),StateDirectorymode 0700,Restart = always. A siblinghc-http-gw/module exists next to it. This is the closest prior art and the reference for our passphrase and readiness handling.
Decision
Slice 2 generates the lair passphrase in
preStartinto$STATE_DIRECTORY(mode 0600,pwgenoropenssl rand), feeds it withholochain --piped < file, usesType = "notify"(verify the conductor’ssd_notifyin the VM; fall back to the port poll only if it does not fire),StateDirectory0700. Credit Holo-Host/holo-host indocs/architecture.md.
Consequences
From #15, section 7, for slice 2 (#3): “passphrase per ADR-016”.
Later record
- #16 reports
Type = "notify"proven in the VM (systemd printsStarted Holochain conductor.only after the conductor’s readiness signal), so the port-poll fallback was not needed. Onmain,modules/holochain-edgenode.nixruns the conductor asType = "notify"by default through theuseSystemdNotifyoption, withType = "simple"when it is set to false. - The credit is in docs/architecture.md § The lair passphrase and readiness.