fix(deploy): align vector bootstrap identity policy

This commit is contained in:
2026-07-12 02:04:57 +02:00
parent 144acf2093
commit 1145ae20bc
11 changed files with 114 additions and 26 deletions
+5
View File
@@ -33,5 +33,10 @@ authentication or new-login verification fails, it exits without changing the de
verification failure also attempts to restore the old database password over the still-open
authenticated connection. After success, run the printed `vector-reconcile`/migration/core command.
`THT_VECTOR_BOOTSTRAP_USER` is authoritative for database initialization, reconciliation, and
rotation; non-default bootstrap role names are supported. Bootstrap, migrator, reader, and writer
secret files must be non-empty and contain no whitespace (including trailing newlines). Rotation
rejects invalid files before contacting PostgreSQL or staging a deployment-file replacement.
Keep the staged new file on the same trusted host, mode `0600`, and retain a secure backup until the
post-rotation reconciliation and application health checks pass.