dd0a846b64
Secrets were per-node SQLite, so a secret written on one node was invisible to the rest of a cluster. G-7's design resolved the "shared SQL store vs Akka replicator" fork to build only the former; both are built here so the choice is a deployment decision (availability vs partition tolerance) rather than a library limitation. Two new packages — ZB.MOM.WW.Secrets.Replicator.SqlServer (shared store, plus a local-store-with-hub mode) and .Replicator.AkkaDotNet (peer-to-peer over distributed pub/sub). Core gains ISecretsStoreMigrator, one shared SecretLastWriterWins predicate so no two stores can disagree on a tie, the transport-agnostic reconciler, and ReplicatingSecretStore — which closes a real gap: nothing had ever called ISecretReplicator.PublishAsync, so the seam was inert and local writes would not have propagated at all. Verified 182 pass / 1 skip / 0 warnings, including 15 live tests against a real SQL Server 2022 (the SQLite suite ported case-for-case, so any behavioural divergence between the stores fails) and a 9-test in-process 2-node Akka cluster over real remoting. A post-build review caught six defects, all fixed and now covered: both replication modes could not resolve from the container (no test had built one), an unbounded fetch that broke past SQL Server's 2100-parameter cap, a poison row that aborted the rest of its batch forever, Enum.Parse on peer input that could restart the actor in a loop, null crypto blobs crossing the trust boundary, and a silently dropped pull-read failure. Packed at 0.2.0 and vulnerability-scanned clean; not yet published to the feed. Claude-Session: https://claude.ai/code/session_01BL2Vu1ESDQ9SCN4gVKkdts
40 lines
1.1 KiB
JSON
40 lines
1.1 KiB
JSON
{
|
|
"planPath": "docs/plans/2026-07-17-secrets-g7-sqlserver-store.md",
|
|
"status": "executed 2026-07-18 with widened scope (both options built as .Replicator.* packages)",
|
|
"tasks": [
|
|
{
|
|
"id": 0,
|
|
"subject": "Task 1: SQL-Server schema + migrator",
|
|
"status": "completed"
|
|
},
|
|
{
|
|
"id": 1,
|
|
"subject": "Task 2: SqlServerSecretStore : ISecretStore",
|
|
"status": "completed",
|
|
"blockedBy": [
|
|
0
|
|
]
|
|
},
|
|
{
|
|
"id": 2,
|
|
"subject": "Task 3: DI store-selection wiring",
|
|
"status": "completed",
|
|
"blockedBy": [
|
|
1
|
|
],
|
|
"note": "Delivered as AddZbSecretsSqlServerStore / AddZbSecretsSqlServerReplication in a standalone package rather than a SecretsOptions.Store enum in core."
|
|
},
|
|
{
|
|
"id": 3,
|
|
"subject": "Task 4: Docs + adoption notes",
|
|
"status": "completed",
|
|
"blockedBy": [
|
|
1
|
|
],
|
|
"note": "docs/operations/clustered-secrets.md covers all three topologies."
|
|
}
|
|
],
|
|
"deferredPhase2": "BUILT 2026-07-18 as ZB.MOM.WW.Secrets.Replicator.AkkaDotNet (no longer deferred).",
|
|
"lastUpdated": "2026-07-18"
|
|
}
|