docs(security): pin privacyidea resolver reconciliation
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02929-244b-7391-b933-c04010e8eedb
This commit is contained in:
tegwick 2026-08-23 15:05:18 +02:00
parent dc21d246e4
commit eec7007c21
2 changed files with 102 additions and 1 deletions

View file

@ -121,7 +121,8 @@ NetKingdom also added the unattended-safe shape of the remaining provider
operation in `sso-mfa/k8s/privacyidea/update-lldap-resolver-live.sh`. It is
explicitly gated by `--apply`, requires an interactive terminal, uses protected
0600 files, updates only `lldap-coulomb`, and emits no credential values. It
has not been run; attended provider-admin reconciliation remains pending.
has not been run; the exact attended runbook is pinned in
`docs/keycape-exposure-resolver-reconciliation.md`.
Do not use `sso-mfa/bootstrap/creds-rotate.sh` through an agent as currently
written: it prints generated replacement values and its signing-key path