fix: harden DWH auth operator guidance
This commit is contained in:
@@ -60,9 +60,9 @@ After the installation is started, use Workspace management from the authenticat
|
||||
clone.
|
||||
2. Confirm that the installation-owned `workspace-secrets` storage remains outside the source
|
||||
repository and contains no credentials in the workspace descriptors.
|
||||
3. Select the workspace and run **Validate workspace** to verify the active descriptor, catalog,
|
||||
3. Select the workspace and run **Validate workspace source** to verify the active descriptor, catalog,
|
||||
Evidence, annotations, and runtime bindings.
|
||||
4. Run **Test connections** only with the approved read-only DWH/Evidence test configuration.
|
||||
4. Run **Test workspace connections** only with the approved read-only DWH/Evidence test configuration.
|
||||
Results are redacted and the workspace source remains unchanged.
|
||||
|
||||
<!-- workspace-descriptor-contract:start -->
|
||||
@@ -118,7 +118,7 @@ and fast-forward candidate checkout. It does not copy anything to the user's com
|
||||
|
||||
### Chiavi DWH REST per installazione
|
||||
|
||||
Se il binding selezionato è `rest_api`, la chiave DWH è una credenziale per questa installazione e si salva nel vault tramite **Save runtime secrets** oppure in un file locale indicato da `API_KEY_FILE`. `postgres_direct` e `ssh_tunnel` non usano questa chiave. Per emissione, TLS, rotazione e verifica `/rpc/ping`, seguire [enrollment DWH REST](dwh-auth-client-enrollment.md).
|
||||
Se il binding selezionato è `rest_api`, la chiave DWH è una credenziale per questa installazione e si salva nel vault tramite **Save entered secrets** oppure in un file locale indicato da `API_KEY_FILE`. `postgres_direct` e `ssh_tunnel` non usano questa chiave. Per emissione, TLS, rotazione e verifica `/rpc/ping`, seguire [enrollment DWH REST](dwh-auth-client-enrollment.md).
|
||||
|
||||
Open Workspace management after the first successful repository update.
|
||||
|
||||
@@ -127,13 +127,13 @@ Open Workspace management after the first successful repository update.
|
||||
tests do.
|
||||
3. Review the runtime fields derived from the selected DWH transport and Evidence authentication
|
||||
mechanism.
|
||||
4. Enter or rotate the required values and choose **Save runtime secrets**.
|
||||
5. Run **Validate workspace** and then **Test connections**.
|
||||
4. Enter or rotate the required values and choose **Save entered secrets**.
|
||||
5. Run **Validate workspace source** and then **Test workspace connections**.
|
||||
|
||||
Secret fields are write-only. The GUI receives only configured/missing status. Values are
|
||||
encrypted by the backend in the platform-neutral `workspace-secrets` volume. ThothII temporarily
|
||||
materializes a restrictive file only while an existing file-oriented connector needs it, then
|
||||
removes that file when the runtime lease ends. **Forget** deletes the selected encrypted value.
|
||||
removes that file when the runtime lease ends. **Forget stored value** deletes the selected encrypted value.
|
||||
|
||||
The workspace YAML stays environment-independent: it declares connector mechanisms, not host
|
||||
paths or credentials. Installation trust material such as a Git CA or `known_hosts` remains an
|
||||
|
||||
Reference in New Issue
Block a user