Harden secret provisioning and lifecycle controls
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a0217e-8c4c-7383-be6b-f50a6e485306
This commit is contained in:
parent
0617923ff1
commit
3a1bd4f1c8
23 changed files with 1369 additions and 162 deletions
|
|
@ -49,8 +49,11 @@ contents in this repo.
|
|||
|
||||
## H4 — Rotation & lifecycle states
|
||||
|
||||
- Implement `rotate`, and explicit `compromised` / `deactivated` lane states with
|
||||
evidence, beyond the current `revoke` (metadata delete).
|
||||
- Implement `rotate` and persistent `compromised` / `deactivated` lane states
|
||||
with evidence. Explicit suspend/deactivate/destroy plans now exist, and
|
||||
ordinary `revoke` safely aliases native AppRole/policy deactivation, but lane
|
||||
state and coordinated provider/workload rotation remain outstanding. Live
|
||||
destroy remains disabled until exact-action authorization is available.
|
||||
|
||||
## H5 — Audit report command
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue