Record registry and offsite backup completion
This commit is contained in:
parent
f8df43a55e
commit
0ffc5af591
1 changed files with 12 additions and 0 deletions
|
|
@ -155,6 +155,18 @@ image and restoration of `user-engine:portal-2bcda7f`. The remaining
|
||||||
production gaps are off-node backup custody and approved registry publication,
|
production gaps are off-node backup custody and approved registry publication,
|
||||||
so this task remains in progress.
|
so this task remains in progress.
|
||||||
|
|
||||||
|
2026-07-30 follow-up: the portal, provisioner, and prior rollback image are
|
||||||
|
published through the workload-scoped Forgejo credential and anonymously
|
||||||
|
verified by digest. The live portal and provisioner now use registry digests,
|
||||||
|
and rollback/roll-forward no longer depends on containerd retaining local
|
||||||
|
tags. An age-encrypted user-engine Postgres dump was uploaded through the
|
||||||
|
established activity-core offsite lane with plaintext cleanup.
|
||||||
|
|
||||||
|
The remaining T05 item is migration of the portal edge marker and provisioner
|
||||||
|
service token from bootstrap Kubernetes Secrets into an OpenBao-owned,
|
||||||
|
ExternalSecret-delivered, rotatable lane. This requires the ops-mason
|
||||||
|
executive approval gate for new secret custody.
|
||||||
|
|
||||||
## T06 - Security, accessibility, and workflow conformance
|
## T06 - Security, accessibility, and workflow conformance
|
||||||
|
|
||||||
```task
|
```task
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue