joshavant
|
ba2eb583c0
|
fix(secrets): make apply idempotent and keep audit read-only
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
f413e314b9
|
feat(secrets): replace migrate flow with audit/configure/apply
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
8944b75e16
|
fix(secrets): align ref contracts and non-interactive ref persistence
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
86622ebea9
|
fix(secrets): enforce file provider read timeouts
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
060ede8aaa
|
test(secrets): skip windows ACL-sensitive file-provider runtime tests
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
b84d7796be
|
test(secrets): skip strict file-permission resolver tests on windows
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
bde9cbb058
|
docs(secrets): align provider model and add exec resolver coverage
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
4e7a833a24
|
feat(security): add provider-based external secrets management
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
bb60cab76d
|
test: sops invocation assertion
Signed-off-by: joshavant <830519+joshavant@users.noreply.github.com>
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
e8637c79b3
|
fix(secrets): harden sops migration sops rule matching
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
0e69660c41
|
feat(secrets): finalize external secrets runtime and migration hardening
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
4d94b05ac5
|
Secrets: keep read-only runtime sync in-memory
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
04aa856fc0
|
Onboard: require explicit mode for env secret refs
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
363334253b
|
Secrets migrate: split plan/apply/backup modules
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
8e439e2d81
|
Secrets migrate: ensure unique backup ids per write
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
a74067d00b
|
Secrets migrate: share helpers and narrow env scrub scope
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
f6a854bd37
|
Secrets: add migrate rollback and skill ref support
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
45ec5aaf2b
|
Secrets: keep read-only runtime sync in-memory
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
8e33ebe471
|
Secrets: make runtime activation auth loads read-only
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
e45729a430
|
Secrets runtime: include sourceConfig in prepared snapshot type
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
e4915cb107
|
Secrets: preserve runtime snapshot source refs on write
|
2026-02-26 14:47:22 +00:00 |
|
joshavant
|
b50c4c2c44
|
Gateway: add eager secrets runtime snapshot activation
|
2026-02-26 14:47:22 +00:00 |
|