Record audit sender OpenBao authority
This commit is contained in:
parent
68c5f0b177
commit
c2af842c55
2 changed files with 11 additions and 4 deletions
|
|
@ -84,10 +84,10 @@ custody defect: stop and investigate.
|
|||
|
||||
## Sender credential rotation
|
||||
|
||||
First deploy mints the registry in-cluster as Secret `audit-core-senders`
|
||||
(ops-mason plan `audit-core-openbao-runtime-custody`). The OpenBao path
|
||||
`platform/workloads/audit-core/senders` is the later authority after a
|
||||
wrap-migrate; do not `bao kv put` it by hand. Rotation is overlap-first:
|
||||
OpenBao path `platform/workloads/audit-core/senders` is the authority for
|
||||
ExternalSecret `audit-core-senders`. The initial in-cluster registry was
|
||||
wrap-migrated on 2026-08-14 without printing or staging its values; do not
|
||||
replace that path with a founder paste. Rotation is overlap-first:
|
||||
|
||||
1. Add the replacement token to the sender's `tokens` list. Both work.
|
||||
2. Move the sender to the new token.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue