fix(secrets): recover encrypted tokens on all backends

This commit is contained in:
2026-07-22 17:31:39 +00:00
committed by claude
parent 28953bfe0b
commit 854f6b5696
25 changed files with 517 additions and 57 deletions
@@ -79,8 +79,11 @@ credential wipe.
upstream credentials.
4. The stored form is revocable and rotatable without relaunching bottles
that are not affected.
5. Reap/teardown destroys a bottle's stored secrets along with its
registry row (no ciphertext outliving its bottle).
5. When the retained bottle record reaches the lifecycle status `removed`,
its stored secrets are destroyed. Status/event persistence and the removal
transition land separately; this interim slice intentionally retains the
ciphertext across today's teardown/reconcile calls until that lifecycle is
available.
6. Migration is transparent: existing bottles keep working, no manifest
changes required.