fix(deploy): align vector bootstrap identity policy
This commit is contained in:
@@ -116,3 +116,18 @@ Final tests:
|
||||
- `./scripts/test-vector-bootstrap-rotation.sh`: PASS
|
||||
- `./scripts/local-vector-smoke.sh`: PASS with negative and positive live bootstrap rotation
|
||||
- existing local-vector collision/safety and Compose deployment contracts: PASS
|
||||
|
||||
## Final identity and secret-policy alignment
|
||||
|
||||
- `THT_VECTOR_BOOTSTRAP_USER` is now passed through core as well as vector-db and reconciliation,
|
||||
so the rotation helper uses the authoritative configured role instead of defaulting to `postgres`.
|
||||
- Rotation and reconciliation source the same raw-file `secret-policy.sh`: non-empty and no
|
||||
whitespace, including trailing newlines. Rotation validates both files before Docker,
|
||||
PostgreSQL, or atomic replacement staging; `test-vector-secret-policy.sh` pins empty, newline,
|
||||
internal-space, and valid metacharacter cases.
|
||||
- Fake-Docker tests prove a non-default identity reaches the helper path and whitespace rejection
|
||||
performs no Docker call and creates no staged replacement.
|
||||
- The real smoke runs the entire stack as `thoth_bootstrap_smoke`. Its whitespace-negative case
|
||||
leaves the deployment file unchanged and proves the existing database login still succeeds;
|
||||
non-default-account bootstrap rotation, reconciliation, migration, core health, restart, and
|
||||
persisted retrieval all pass.
|
||||
|
||||
Reference in New Issue
Block a user