Contain backup upload credentials and prepare provider recovery gates
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 2s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
codex 2026-09-05 19:21:06 +02:00
parent 08a406f2f8
commit 5ef016be01
6 changed files with 219 additions and 14 deletions

View file

@ -32,6 +32,9 @@ There is no built-in credential fallback. Missing credentials stop execution
before any cluster dump. Local encryption dry-runs skip upload authentication.
Provider rotation and replacement upload/restore proof are tracked separately
in `RPF-WP-0029`; removing the source default does not prove revocation.
The concrete owner procedure is `docs/backup-credential-recovery.md`. Upload
credentials and credential-bearing URLs are passed to curl through stdin,
and backend errors never print those values. Redirects are refused.
Decrypt: `~/.config/age/railiance-backup.key` (same key as other Railiance backups).