Prove OpenBao isolated restore
This commit is contained in:
parent
b8fdc4aa45
commit
7fd89ad6b0
4 changed files with 64 additions and 5 deletions
|
|
@ -36,9 +36,14 @@ approved offsite backup lane. Its non-secret fingerprints are:
|
|||
|
||||
A second fresh snapshot restored successfully into an isolated OpenBao 2.5.4
|
||||
pod on railiance01. OpenBao correctly resealed immediately after restore under
|
||||
the source Shamir barrier. Full semantic and restart validation therefore
|
||||
requires the source 2-of-3 unseal quorum; the temporary instance was not made
|
||||
serving. The empty target Helm release has been aligned from 2.5.3 to 2.5.4.
|
||||
the source Shamir barrier. On 2026-08-03 the operator supplied the rotated
|
||||
2-of-3 quorum through hidden prompts. Two restart/unseal cycles passed; the
|
||||
restored cluster became active with the source cluster ID, its inventory
|
||||
matched, a scoped AppRole proved exact-path read and sibling denial, and the
|
||||
declarative file audit device wrote successfully. Evidence is in
|
||||
`docs/evidence/openbao-isolated-restore-2026-08-03.json`. The disposable
|
||||
instance and plaintext staging were then removed. The empty target Helm release
|
||||
has been aligned from 2.5.3 to 2.5.4.
|
||||
|
||||
## Preconditions and abort points
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue