Schedule OpenBao retention closeout

This commit is contained in:
codex 2026-08-04 00:53:34 +02:00
parent e24b3591a7
commit a89019eae1
4 changed files with 38 additions and 6 deletions

View file

@ -21,7 +21,7 @@ not run on Knative or scale to zero.
- The source remains unsealed and authoritative until the target passes two
restart/unseal cycles and all private consumer waves pass. During cutover it
is write-frozen, then scaled to zero while its PVCs, audit PVC, manifests,
TLS material, and encrypted snapshot remain retained for at least 30 days.
TLS material, and encrypted snapshot remain retained for at least 14 days.
## Proven preparation
@ -94,7 +94,7 @@ railiance01 API and reviewer identity before use.
snapshot over the retained source without a new reviewed recovery plan.
- Target RTO is 60 minutes from an abort decision. RPO is the bounded final
write-freeze window; the intended RPO is zero acknowledged writes.
- Keep the stopped source state and final encrypted snapshot for at least 30
- Keep the stopped source state and final encrypted snapshot for at least 14
days. PVC, Raft, Secret, audit, or TLS deletion requires fresh explicit
approval after a successful railiance01 disaster-recovery drill.