Record the deferred rotation and its triggers (CUST-WP-0073).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 352750@bnt-lap001 Assistant-Session: de41ef1c-2113-4dd2-9b92-f318ffa7f98b
This commit is contained in:
parent
49565a345b
commit
004a72cd5c
1 changed files with 6 additions and 0 deletions
|
|
@ -168,6 +168,12 @@ bind password and the Authelia client secret. The other three Secrets were
|
||||||
probably printed as well. All four must be treated as exposed and rotated; the
|
probably printed as well. All four must be treated as exposed and rotated; the
|
||||||
annotation cleanup folds into that rotation.
|
annotation cleanup folds into that rotation.
|
||||||
|
|
||||||
|
**Rotation deferred (founder decision, 2026-09-24, builder mode).** Tracked as
|
||||||
|
the-custodian `CUST-WP-0073-T05` with event triggers: the first production
|
||||||
|
workload or customer data, any sign the transcript left the workstation, or a
|
||||||
|
planned key rotation. The same workplan removes the problem class by giving
|
||||||
|
agents a cluster identity that cannot read these objects at all.
|
||||||
|
|
||||||
## Unreleased fail-closed startup changes (read before the next rollout)
|
## Unreleased fail-closed startup changes (read before the next rollout)
|
||||||
|
|
||||||
The deployed image at the time of writing is
|
The deployed image at the time of writing is
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue