feat: complete evidence restructuring worktree
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
# Enrollment client per DWH REST
|
||||
# DWH REST client enrollment
|
||||
|
||||
La credenziale `dwh-auth` appartiene a una installazione ThothII e serve soltanto quando il
|
||||
workspace usa il trasporto `rest_api`.
|
||||
The `dwh-auth` credential belongs to one ThothII installation and is needed only when the
|
||||
workspace uses the `rest_api` transport.
|
||||
|
||||
| Trasporto | Materiale richiesto |
|
||||
| --- | --- |
|
||||
@@ -9,13 +9,13 @@ workspace usa il trasporto `rest_api`.
|
||||
| `postgres_direct` | Credenziali PostgreSQL e configurazione TLS PostgreSQL |
|
||||
| `ssh_tunnel` | Credenziali PostgreSQL e materiale SSH |
|
||||
|
||||
## Consegna e conservazione
|
||||
## Delivery and storage
|
||||
|
||||
Ricevere chiave e CA attraverso canali protetti separati. Conservare la chiave nel vault
|
||||
dell'installazione o in un file regolare accessibile soltanto all'account autorizzato. Non
|
||||
inserirla in Git, file YAML, argomenti, log o schermate condivise.
|
||||
Receive the key and CA through separate protected channels. Store the key in the installation
|
||||
vault or in a regular file accessible only to the authorized account. Do not put it in Git, YAML
|
||||
files, arguments, logs, or shared screens.
|
||||
|
||||
## Configurazione ACME Limited
|
||||
## ACME Limited configuration
|
||||
|
||||
Esempio di binding headless per il workspace `acme-ebikes`:
|
||||
|
||||
@@ -26,16 +26,14 @@ THT_WS_ACME_EBIKES_DWH_API_KEY_FILE=/run/secrets/acme-ebikes-dwh-api-key
|
||||
THT_WS_ACME_EBIKES_DWH_TLS_CA_FILE=/run/secrets/acme-ebikes-dwh-ca.pem
|
||||
```
|
||||
|
||||
Il suffisso del workspace deriva dall'ID immutabile trasformando i trattini in underscore e
|
||||
usando lettere maiuscole. `API_KEY_FILE` contiene il percorso del file montato, non il valore
|
||||
della chiave.
|
||||
The workspace suffix comes from the immutable ID, with hyphens changed to underscores and letters
|
||||
converted to uppercase. `API_KEY_FILE` contains the mounted file path, not the key value.
|
||||
|
||||
## Rotazione e revoca
|
||||
## Rotation and revocation
|
||||
|
||||
Durante la rotazione, ricevere la nuova generazione, aggiornare il vault o il file montato e
|
||||
confermare la connettività sulla route innocua `/rpc/ping`. Solo dopo questa conferma il
|
||||
responsabile del server revoca la generazione precedente.
|
||||
During rotation, receive the new generation, update the vault or mounted file, and confirm
|
||||
connectivity through the harmless `/rpc/ping` route. The server owner revokes the previous
|
||||
generation only after this confirmation.
|
||||
|
||||
Un `401` indica una chiave assente, sconosciuta, scaduta o revocata. Un `503` indica che il
|
||||
servizio di autorizzazione o il registro non sono disponibili. In entrambi i casi non aggirare
|
||||
REST e non ridurre la verifica TLS.
|
||||
A `401` means the key is missing, unknown, expired, or revoked. A `503` means the authorization
|
||||
service or registry is unavailable. In either case, do not bypass REST or weaken TLS verification.
|
||||
|
||||
Reference in New Issue
Block a user