Skip to content

Secrets hardening: context-bound envelopes (enc:v2), key rotation walk, audit stream #1552

Description

@kriszyp

Hardening phase (5) of the secrets-management plan, after the store (#715), consumption, and custody (harper-pro#166) land.

  • enc:v2: AAD-bind ciphertext to its context (cluster | secret name) so a transplanted envelope fails to decrypt.
  • Rotation: operator-triggered re-encrypt walk over hdb_secret keyed on envelope kid; custody layer holds a kid→key set during the walk so old ciphertext keeps decrypting until re-encrypted.
  • First-class audit stream for secret writes/grants/reads (component-granularity for reads) — who/what/when, never values.
  • External KMS/vault custody provider (Integrate Key Vault as a source for environment variable secrets #816) belongs to this phase.

🤖 Drafted by Claude (Fable 5) on Kris's behalf.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Fields

Priority

P2

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions