hub v0.127.0: off-site key registrar (box never gets the storage password), password sealed at rest, daily key check, clean-up window (shipped off) — decisions 68-69, R-820/R-821/R-822
gates / gates (push) Successful in 29s
gates / gates (push) Successful in 29s
Part A evidence (migration spike, sftp-written repo through the pinned rclone key) and the hub red-proofs under documentation/audits/offsite-lock-build-2026-10-03/. Manifest bump follows after the image is built and Secret/offsite-secret-key exists. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -117,6 +117,29 @@ shred -u /path/to/keyfile
|
||||
|
||||
---
|
||||
|
||||
## Off-site password sealing key — `Secret/offsite-secret-key` (hub v0.127.0, decision 69, R-821)
|
||||
|
||||
**What uses it:** `hub` env `OFFSITE_SECRET_KEY` (64 hex characters = 32 bytes). It seals every Storage Box
|
||||
sub-account password in `one_time_secrets.value`; the hub's key registrar opens them to write box keys.
|
||||
**Required** — the pod does not start without it.
|
||||
|
||||
**Create (once, before the first v0.127.0 sync) — the value never touches a file or the terminal:**
|
||||
|
||||
```bash
|
||||
sudo kubectl -n felhom-system create secret generic offsite-secret-key \
|
||||
--from-literal=OFFSITE_SECRET_KEY="$(openssl rand -hex 32)"
|
||||
```
|
||||
|
||||
**If it is lost:** the sealed passwords cannot be opened. Nothing on the boxes breaks (their keys are installed);
|
||||
the registrar and the daily check fail with `offsite_key_audit_failed`. Recover per customer with the hub's
|
||||
**Re-issue offsite credentials** button (the provider resets the password; the hub seals the new one). Keep a copy
|
||||
in the operator's password manager if a Re-issue round is not acceptable.
|
||||
|
||||
**Rotation:** not built. A new key cannot open the old rows; rotate by setting the new key and pressing Re-issue
|
||||
for every off-site customer.
|
||||
|
||||
---
|
||||
|
||||
## Other committed secrets (tracked, NOT yet de-gitted — backlog)
|
||||
|
||||
`manifests/felhom.secret.yaml` still commits other plaintext secrets (`healthchecks-config` `SECRET_KEY`
|
||||
|
||||
Reference in New Issue
Block a user