fix(deploy): validate session migrator TLS mode
This commit is contained in:
@@ -230,6 +230,8 @@ The overlay mounts the runtime password at `/run/secrets/session_runtime_passwor
|
||||
It mounts `session_migrator_password` only to `session-migrate`. The backend refuses a server
|
||||
session store without upstream authentication, direct DB host/name/runtime user/password-file,
|
||||
`verify-ca` or `verify-full`, and an absolute CA path.
|
||||
The migrator independently rejects every other TLS mode before reading its password secret or
|
||||
constructing a database URL.
|
||||
|
||||
Perform the cutover in one maintenance window, with the Task 4 portal proxy headers and Task 5
|
||||
backend principal parser deployed together. Neither change is safe to deploy independently: Task
|
||||
|
||||
Reference in New Issue
Block a user