# Task 3 report — one secret bundle for local services ## Status Complete. Local pgvector bootstrap, reconciliation, migration, and preprocess services now mount only `/run/secrets/thothii.secrets`. `deploy/vector/secret-policy.sh` validates the whole bundle (allowlist, duplicate/empty/unknown keys, comments/blank lines, mode and symlink policy) and returns only the requested value. The core entrypoint exposes DWH/vector/CA values to the harness and materializes short-lived 0600 password files for workspace resolution. ## TDD evidence - RED: `./scripts/test-preprocess-compose-config.sh` failed on the pre-existing `vector_reader_password` Compose secret declaration. - GREEN: the same command passes after the bundle conversion and verifies local-vector workspace interpolation and shared secret mounts. - `./scripts/test-vector-secret-policy.sh` covers comments/blank lines and rejects an unrelated duplicate key. ## Verification - `./scripts/test-vector-secret-policy.sh` — passed. - `./scripts/test-preprocess-compose-config.sh` — passed. - `./scripts/test-vector-backup-restore-safety.sh` — passed. - `./scripts/test-default-compose.sh` — passed. - `./scripts/test-container-deployment.sh` — passed. - `./scripts/local-vector-smoke.sh` — passed with real Docker (bootstrap rotation, role reconciliation, migration, persistence and restart). - `./scripts/preprocess-smoke.sh` — passed with real Docker (unchanged rerun, mutation, DWH job, ACTIVE publication and cleanup). - `./scripts/preprocess-smoke.sh --cleanup-failure` — passed. - `git diff --check` and `sh -n` gates — passed. ## Critical review fix `buildPiChildEnv` now removes `THT_DWH_API_KEY`, `THT_VEC_API_KEY`, `THT_VEC_WRITE_API_KEY`, `THT_SSL_CA`, `THT_CA`, and their file metadata before spawning Pi. A regression test proves that neither secret values nor bundle/file metadata are inherited by the Pi child. ## Commits - `70a19f2 feat(compose): use one secret bundle for local services` - `d500563 fix(security): scrub deployment secrets from Pi child` - `8518a73 fix(security): scrub raw deployment secret values` ## Concern The rotation helper retains its old/new scratch-file CLI contract; smoke tests keep those files outside Compose and mount only the bundle. ## Whole-branch review fixes - `core-entrypoint.sh` validates `THT_SECRETS_FILE` fail-closed before optional lookups; malformed, duplicate, unknown, oversized, or overlong bundles stop startup with sanitized diagnostics. - Runtime password files are cleaned after child exit via signal forwarding and `wait`, rather than being orphaned by `exec`. - The shell loader accepts CRLF bundles (Windows/Notepad) consistently with the TypeScript loader. - Optional key lookup distinguishes an absent key from an invalid value; present malformed credentials now stop entrypoint startup instead of being silently ignored.