fix(deploy): validate session migrator TLS mode

This commit is contained in:
User
2026-07-16 19:07:53 +02:00
parent cadc4c6947
commit 7a65fc80a2
6 changed files with 96 additions and 8 deletions
+2
View File
@@ -230,6 +230,8 @@ The overlay mounts the runtime password at `/run/secrets/session_runtime_passwor
It mounts `session_migrator_password` only to `session-migrate`. The backend refuses a server
session store without upstream authentication, direct DB host/name/runtime user/password-file,
`verify-ca` or `verify-full`, and an absolute CA path.
The migrator independently rejects every other TLS mode before reading its password secret or
constructing a database URL.
Perform the cutover in one maintenance window, with the Task 4 portal proxy headers and Task 5
backend principal parser deployed together. Neither change is safe to deploy independently: Task