Commit Graph

1 Commits

Author SHA1 Message Date
didericis 46e595ffb1 docs(prd): draft encrypted at-rest egress secrets (SecretProvider interim)
tracker-policy-pr / check-pr (pull_request) Successful in 11s
The orchestrator holds each bottle's egress auth tokens in process memory
only, so recreating the infra container strips every already-running
bottle of its upstream credentials. The registry row and the gateway CA
both survive; the tokens do not, so /resolve serves an intact policy with
an empty token map and the addon fails closed on `token_env unset`.

Drafts the interim slice of #355: persist the tokens encrypted so they
survive a restart, without regressing to plaintext at rest and without
foreclosing the per-request minting end state. Design section is left for
the author to fill in.
2026-07-21 19:22:24 -04:00