Contain backup upload credentials and prepare provider recovery gates
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a06ecb-456a-71c2-b41e-0755d336e883
This commit is contained in:
parent
08a406f2f8
commit
5ef016be01
6 changed files with 219 additions and 14 deletions
|
|
@ -32,6 +32,9 @@ There is no built-in credential fallback. Missing credentials stop execution
|
|||
before any cluster dump. Local encryption dry-runs skip upload authentication.
|
||||
Provider rotation and replacement upload/restore proof are tracked separately
|
||||
in `RPF-WP-0029`; removing the source default does not prove revocation.
|
||||
The concrete owner procedure is `docs/backup-credential-recovery.md`. Upload
|
||||
credentials and credential-bearing URLs are passed to curl through stdin,
|
||||
and backend errors never print those values. Redirects are refused.
|
||||
|
||||
Decrypt: `~/.config/age/railiance-backup.key` (same key as other Railiance backups).
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue