# Database dynamic credentials ## Worker checklist This file is a pointer only. ops-warden does not issue database credentials and does not duplicate the operating procedure. - Package and authoritative procedure: `rapp-postgres/wiki/playbooks/database-dynamic-credentials.md#worker-checklist` - Consumer/isolation decision: `rapp-postgres/docs/adr/ADR-0001-consumer-boundary-and-tenant-isolation.md` - Credential engine and grant catalog owner: `railiance-platform` - Canon draft: `rapp-postgres/docs/canon-drafts/shared-platform-relational-storage_v0.1-draft.md` Never place a database password, credential-bearing DSN, lease value, or bootstrap token in Git, State Hub, logs, or chat.