Record registry and offsite backup completion
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

This commit is contained in:
tegwick 2026-07-30 00:25:34 +02:00
parent f8df43a55e
commit 0ffc5af591

View file

@ -155,6 +155,18 @@ image and restoration of `user-engine:portal-2bcda7f`. The remaining
production gaps are off-node backup custody and approved registry publication,
so this task remains in progress.
2026-07-30 follow-up: the portal, provisioner, and prior rollback image are
published through the workload-scoped Forgejo credential and anonymously
verified by digest. The live portal and provisioner now use registry digests,
and rollback/roll-forward no longer depends on containerd retaining local
tags. An age-encrypted user-engine Postgres dump was uploaded through the
established activity-core offsite lane with plaintext cleanup.
The remaining T05 item is migration of the portal edge marker and provisioner
service token from bootstrap Kubernetes Secrets into an OpenBao-owned,
ExternalSecret-delivered, rotatable lane. This requires the ops-mason
executive approval gate for new secret custody.
## T06 - Security, accessibility, and workflow conformance
```task