Files
scadaproj/components/secrets
Joseph Doherty baea6cc2e0 docs(secrets): interactive-console quickstart + discoverability sweep
- new task-first quickstart (deployment seeding + KEK-lockout walkthroughs)
- runbook: document the sixth ReferenceStatus (PresentUnverified) + quickstart link
- README + shared-contract + umbrella CLAUDE.md secrets row updated for 0.3.0 console
- CLI usage text now mentions the interactive console (was undiscoverable from --help)
2026-07-19 14:55:53 -04:00
..

Secrets (encrypted secret store + ${secret:} resolution)

Normalizes how the family stores and consumes secrets — SQL/login passwords, API-key HMAC peppers, LDAP bind passwords, connection strings, TLS material — which are handled ad-hoc and inconsistently across the three apps today (Data-Protection-encrypted connection strings in ScadaBridge; peppers/passwords in environment variables; LDAP passwords in appsettings).

The goal is the shared ZB.MOM.WW.Secrets library: AES-256-GCM envelope encryption at rest, a pluggable master-key provider and store, an audited ISecretResolver + ${secret:name} config expander for app runtime, and a Blazor /admin/secrets management UI. The library is built, published (0.1.2), and live-proven via its reference consumer; per-app adoption is the tracked follow-on.

Status

State
Library Built + publishedZB.MOM.WW.Secrets{,.Abstractions,.Ui} 0.1.2 on the dohertj2-gitea feed; .Cli in-repo (not packed); .Akka replicator deferred (design only)
Reference consumer HistorianGateway — adopted + live-proven (2026-07-16): historian password sourced via ${secret:}, authenticated read against the real wonder historian
Three sister apps Not yet adopted — see per-app current-state + GAPS

Per-project current state

Project Today (baseline) Doc
OtOpcUa (code-verified baseline) current-state/otopcua/CURRENT-STATE.md
MxAccessGateway (code-verified baseline) current-state/mxaccessgw/CURRENT-STATE.md
ScadaBridge (code-verified baseline) current-state/scadabridge/CURRENT-STATE.md

Not applicable as a fourth adopter row but the exemplar: HistorianGateway already consumes the lib — its wiring is the template the three apps follow (see the shared-contract "Consumer wiring" section).