fix: harden DWH auth operator guidance

This commit is contained in:
User
2026-08-21 04:28:20 +02:00
parent 7b9b8b308d
commit 707c13d781
14 changed files with 196 additions and 56 deletions
@@ -684,8 +684,9 @@ PostgREST; include no literal key.
- [ ] **Step 3: Validate before reload**
Run structural checker, secret scan without match output, bounded diff, install candidates,
`sudo nginx -t`. On failure restore backups before reload and record sanitized FAIL.
Run the structural checker and a secret scan that emits only PASS/FAIL metadata, install candidates,
and run `sudo nginx -t`. Never run or retain a raw diff, `nginx -T`, or configuration dump: a legacy
Nginx file can contain the exposed key. On failure restore backups before reload and record sanitized FAIL.
- [ ] **Step 4: Reload/prove dual-key**
@@ -696,7 +697,7 @@ change.
- [ ] **Step 5: Deliver/configure Mac**
Use approved protected channel. Verify CA fingerprint, configure vault or headless `API_KEY_FILE`,
run Workspace Validate, Test connections, `/rpc/ping`. Record public IDs, fingerprint confirmation,
run **Validate workspace source**, **Test workspace connections**, `/rpc/ping`. Record public IDs, fingerprint confirmation,
timestamp, result only.
- [ ] **Step 6: Observe/revoke legacy**