fix(deploy): align vector bootstrap identity policy
This commit is contained in:
@@ -33,5 +33,10 @@ authentication or new-login verification fails, it exits without changing the de
|
||||
verification failure also attempts to restore the old database password over the still-open
|
||||
authenticated connection. After success, run the printed `vector-reconcile`/migration/core command.
|
||||
|
||||
`THT_VECTOR_BOOTSTRAP_USER` is authoritative for database initialization, reconciliation, and
|
||||
rotation; non-default bootstrap role names are supported. Bootstrap, migrator, reader, and writer
|
||||
secret files must be non-empty and contain no whitespace (including trailing newlines). Rotation
|
||||
rejects invalid files before contacting PostgreSQL or staging a deployment-file replacement.
|
||||
|
||||
Keep the staged new file on the same trusted host, mode `0600`, and retain a secure backup until the
|
||||
post-rotation reconciliation and application health checks pass.
|
||||
|
||||
Reference in New Issue
Block a user