repo.work.assign_missing_identifiers
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s

source: repo-manager
reason: deterministic projection registration

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
repo-manager 2026-09-05 09:41:10 +02:00
parent c7b0b3f572
commit 05f315be84
3 changed files with 9 additions and 0 deletions

View file

@ -8,6 +8,7 @@ status: blocked
owner: codex
created: "2026-09-05"
updated: "2026-09-05"
state_hub_workstream_id: "bb326ebb-a313-549e-b35f-1bf17e1c58fd"
---
# Remove backup credential default and verify governed replacement
@ -21,6 +22,7 @@ on 2026-09-05. Repository implementation is complete; live closure remains pendi
id: RPF-WP-0029-T01
status: done
priority: high
state_hub_task_id: "4b5aefdb-a746-54f9-ba29-ebb840e7848d"
```
Removed the literal upload credential default from tools/cmd/forgejo-backup. Missing governed input now fails before cluster operations with a value-free diagnostic; encryption dry-runs skip upload authentication. Offline tests prove missing-input denial, explicit input, and mocked OpenBao resolution.
@ -31,6 +33,7 @@ Removed the literal upload credential default from tools/cmd/forgejo-backup. Mis
id: RPF-WP-0029-T02
status: wait
priority: high
state_hub_task_id: "b3f3402f-890b-5781-9b3e-1c9c0d28cea8"
```
Provider-side invalidation and replacement custody need the attended provider owner and CCR-2026-0004 lifecycle procedure. Record only non-secret invalidation, encrypted upload and restore receipts. No provider authority or replacement receipt was available; source removal alone does not close the reported exposure. Never record the predecessor value, fingerprint, length, or shape.