fix(deploy): support bootstrap password rotation
This commit is contained in:
@@ -14,3 +14,24 @@ docker compose -f compose.yaml -f deploy/compose.production.yaml \
|
||||
|
||||
The CA file should contain only the public PEM certificate chain. API-key files should contain
|
||||
one value with no surrounding quotes.
|
||||
|
||||
## Rotating the initialized local-vector bootstrap password
|
||||
|
||||
Replacing `THT_VECTOR_BOOTSTRAP_PASSWORD_SECRET_FILE` or changing its contents does **not** rotate
|
||||
an initialized PostgreSQL cluster. Use the supported workflow against the running local-vector
|
||||
project:
|
||||
|
||||
```sh
|
||||
./scripts/vector-rotate-bootstrap-password.sh \
|
||||
/absolute/path/to/current-bootstrap-secret \
|
||||
/absolute/path/to/staged-new-bootstrap-secret
|
||||
```
|
||||
|
||||
The command authenticates using the current file, changes only the authenticated bootstrap role,
|
||||
verifies a new login, and only then atomically replaces the current deployment secret file. If old
|
||||
authentication or new-login verification fails, it exits without changing the deployment file;
|
||||
verification failure also attempts to restore the old database password over the still-open
|
||||
authenticated connection. After success, run the printed `vector-reconcile`/migration/core command.
|
||||
|
||||
Keep the staged new file on the same trusted host, mode `0600`, and retain a secure backup until the
|
||||
post-rotation reconciliation and application health checks pass.
|
||||
|
||||
Reference in New Issue
Block a user