fix(deploy): support bootstrap password rotation
This commit is contained in:
@@ -86,3 +86,33 @@ Follow-up verification:
|
||||
Remaining operational constraint: the bootstrap admin secret must continue to match the PostgreSQL
|
||||
bootstrap account stored in the volume. Runtime migrator/reader/writer rotation is supported without
|
||||
data deletion; bootstrap-account password rotation is a distinct database-administration operation.
|
||||
|
||||
## Final hardening — bootstrap account rotation
|
||||
|
||||
The remaining operational constraint is now covered by
|
||||
`scripts/vector-rotate-bootstrap-password.sh OLD_SECRET_FILE NEW_SECRET_FILE`:
|
||||
|
||||
- It does not rely on `POSTGRES_PASSWORD_FILE` after initialization.
|
||||
- It pre-stages the deployment-file replacement in the same directory, authenticates to the live
|
||||
database with the explicit old file, and changes only the authenticated bootstrap role.
|
||||
- Passwords are passed as connection parameters and rendered with psycopg2 SQL composition, so
|
||||
shell and SQL metacharacters are not interpolated.
|
||||
- A second connection must authenticate with the new password before the command succeeds. If that
|
||||
verification fails, the still-open old connection restores the old database password.
|
||||
- Only after verified database login does an atomic rename replace the current deployment secret.
|
||||
Wrong-old authentication and verification failures leave deployment configuration unchanged.
|
||||
|
||||
Final live smoke evidence on one existing `vector_data` volume:
|
||||
|
||||
- wrong-old bootstrap rotation rejected; current deployment secret unchanged
|
||||
- bootstrap password with quote characters rotated successfully
|
||||
- old bootstrap login rejected and new login accepted
|
||||
- `vector-reconcile`, packaged migrations, and core health passed afterward
|
||||
- the vector record written before rotation remained searchable after rotation and after a further
|
||||
database/core restart
|
||||
|
||||
Final tests:
|
||||
|
||||
- `./scripts/test-vector-bootstrap-rotation.sh`: PASS
|
||||
- `./scripts/local-vector-smoke.sh`: PASS with negative and positive live bootstrap rotation
|
||||
- existing local-vector collision/safety and Compose deployment contracts: PASS
|
||||
|
||||
Reference in New Issue
Block a user