docs: truth sweep — retire stale registers, reconcile ledgers with shipped state
- deferred.md: DELETED (git rm) — stale 2026-07-10 duplicate of the canonical deferred-work register; this completes archreview R2-08 T11 (the file was tracked, not untracked as the task assumed) - ScadaBridge-docs-issues.md, ScadaBridge-docs-fixed.md: DELETED (git rm) — generated 2026-07-10 CommentChecker reports, already consumed; completes R2-08 T13 (also tracked, not untracked) - stillpending.md: prepended historical-snapshot banner (2026-06-15 audit; Tier-1 table is not current open work) - docs/plans/phase-8-checklist.md: replaced the unevidenced 'Complete / All passing' stub with the honest state per register row 25 (WP-4 target-scale load test never run) - archreview/plans/00-MASTER-TRACKER.md: R2-01 T2 live failover drill annotated RESOLVED 2026-08-01 (PLAN-R2-01 T4 + docker/failover-drill.sh + SbrFailoverTests); R2-08 T11/T13 recorded completed by this sweep - docs/plans/2026-07-22-clusterclient-to-grpc-plan.md: P3 deferred-RPCs note updated (all four live-proven 2026-08-01,1c99d6fa); ClusterClientSiteAuditClient naming follow-up marked DONE (63c16d69) - docs/plans/2026-05-28-opcua-tag-browser.md.tasks.json: Task 19 flipped to completed (manual smoke PASS 2026-08-01,6dc5d94c) - archreview/plans/PLAN-R2-0[1-8]*.tasks.json: all-pending manifests reconciled with the authoritative tracker (round 2 merged @1930f19b) — flipped to completed except R2-08 T1/T2 which remain pending needs-user - docs/operations/2026-07-16-secrets-clustered-master-key.md: correction banner (SQL-hub replication shipped 8e12f994; KEK-rotation + clustered-secrets runbooks ship with ZB.MOM.WW.Secrets) - docs/plans/2026-07-19-localdb-phase2-live-gate.md: external-system-delete observation annotated RESOLVED (2d03f2d5reconciles deletions incl. external_systems) Claude-Session: https://claude.ai/code/session_014WNM4vjoVksyyBraTXSZE1
This commit is contained in:
@@ -1,5 +1,17 @@
|
||||
# Secrets: Clustered Master-Key Posture (Central Pair)
|
||||
|
||||
> **Update 2026-08-07 (truth sweep):** two claims below are stale.
|
||||
> (1) "there is no built-in cross-node replication today" — cross-node replication
|
||||
> has since shipped: ScadaBridge adopted opt-in **SQL-Server hub replication** for
|
||||
> the host secret store (commit `8e12f994`, "feat(secrets): opt-in SQL-Server hub
|
||||
> replication for the host secret store"; `ZB.MOM.WW.Secrets` 0.2.x Replicator
|
||||
> packages), covered by the shared library's clustered-secrets runbook
|
||||
> (`scadaproj/ZB.MOM.WW.Secrets/docs/operations/clustered-secrets.md`).
|
||||
> (2) the G-8 KEK-rotation runbook is no longer "not yet built" — it ships with the
|
||||
> shared library at `scadaproj/ZB.MOM.WW.Secrets/docs/operations/kek-rotation.md`
|
||||
> (lib 0.1.3, `Rewrap`/`rewrap-all`). The interim shared-volume posture below
|
||||
> remains valid but is no longer the only option.
|
||||
|
||||
## Purpose
|
||||
|
||||
`ZB.MOM.WW.Secrets` resolves `${secret:...}` tokens in `appsettings.*.json` via a
|
||||
|
||||
Reference in New Issue
Block a user