Fix rotation review evidence and reconcile blocked S1 workplans
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e3b9-b19e-7ba1-9eb4-4faea76af3ea
This commit is contained in:
parent
41f25fe42d
commit
9886567b40
10 changed files with 255 additions and 18 deletions
|
|
@ -8,6 +8,8 @@ python3 scripts/sops_rotation.py --check
|
|||
|
||||
It compares each protected file's public age-recipient metadata with the first
|
||||
matching rule in `.sops.yaml`. CI runs this check to detect recipient drift.
|
||||
The JSON output includes the exact file paths, ciphertext SHA-256 hashes, and
|
||||
before/after recipient sets. Run without `--check` to inspect proposed drift.
|
||||
|
||||
An attended non-printing decryption check may emit a receipt:
|
||||
|
||||
|
|
@ -21,7 +23,10 @@ receipt or command output.
|
|||
|
||||
Actual key updates require `--apply` and an approval YAML containing
|
||||
`approved: true`, `approved_by`, `approved_at`, and an exact `changes` list from
|
||||
the current plan. The command fails if that list differs from current metadata.
|
||||
the current plan (including each changed file's `sha256`). The command fails if
|
||||
that list differs from current metadata or the reviewed ciphertext has changed.
|
||||
Applied receipts retain the reviewed before/after recipient sets and original
|
||||
ciphertext hash, plus `after_sha256` for the resulting ciphertext.
|
||||
Review and preserve recovery-key custody before approving recipient removal.
|
||||
Start from `docs/sops-rotation-approval.example.yaml`; the committed example is
|
||||
deliberately unapproved and contains no usable recipient.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue