Feature: SOP — Document secrets management flow and rotation runbook [DUPLICATE — already exists] #231
Labels
No labels
domain:backend
domain:devops
domain:frontend
status:approved
status:in-progress
status:needs-fix
status:qa
type:bug
type:devops
type:feature
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
forgejo_admin/pal-e-platform#231
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Type
Feature
Lineage
Standalone — discovered during session fixing basketball-api deployment. Env var mismatch exposed lack of documented secrets flow.
Repo
forgejo_admin/pal-e-platform(SOP note created via pal-e-docs MCP tools)User Story
As a superadmin
I want the secrets flow documented with a rotation runbook
So that I can audit, rotate, and recover secrets without guessing which source is authoritative
Context
Secrets live in 5 locations with no single document explaining the flow:
~/secrets/pal-e-platform/secrets.envsalt/pillar/secrets/platform.slsterraform/secrets.auto.tfvars*.tfvars)tofu applypal-e-deployments/overlays/*.enc.yamlNote:
secrets.auto.tfvarsis already gitignored (root.gitignorehas*.tfvars).secrets_registry.slscontains only metadata, no actual secret values.File Targets
This ticket creates pal-e-docs content, not repo files:
sop-secrets-management— full flow documentationsecrets_registry.slsas input)Acceptance Criteria
Test Expectations
get_note(slug="sop-secrets-management")Constraints
secrets_registry.slsas the input for the secret inventoryChecklist
Related
project-pal-e-platform— platform infrastructureforgejo_admin/pal-e-deployments #69— env var mismatch that exposed this gapFeature: Document secrets flow and add redundancy across salt/terraform/k8sto Feature: SOP — Document secrets management flow and rotation runbookFeature: SOP — Document secrets management flow and rotation runbookto Feature: SOP — Document secrets management flow and rotation runbook [DUPLICATE — already exists]