Files
scadaproj/components/secrets
Joseph Doherty b009507e10 docs(secrets): OtOpcUa G-2 live-proven vs prod MxGateway (wonder-app-vd03:5120)
Record the OtOpcUa live wonder gate (item 2). A throwaway harness drove OtOpcUa's
real GalaxyDriverBrowser (secret: ApiKeySecretRef resolved via ISecretResolver) against
the real production MxGateway: dummy secret: ref -> MxGatewayAuthenticationException,
real metadata:read key -> CONNECTED + browsed the real Galaxy root (10 nodes). Temp key
minted via the dashboard, then revoked (functionally proven) + deleted; no prod key
touched; harness + scratch stores destroyed. All four apps now G-2..G-6 done + live-proven.
2026-07-16 23:15:00 -04:00
..

Secrets (encrypted secret store + ${secret:} resolution)

Normalizes how the family stores and consumes secrets — SQL/login passwords, API-key HMAC peppers, LDAP bind passwords, connection strings, TLS material — which are handled ad-hoc and inconsistently across the three apps today (Data-Protection-encrypted connection strings in ScadaBridge; peppers/passwords in environment variables; LDAP passwords in appsettings).

The goal is the shared ZB.MOM.WW.Secrets library: AES-256-GCM envelope encryption at rest, a pluggable master-key provider and store, an audited ISecretResolver + ${secret:name} config expander for app runtime, and a Blazor /admin/secrets management UI. The library is built, published (0.1.2), and live-proven via its reference consumer; per-app adoption is the tracked follow-on.

Status

State
Library Built + publishedZB.MOM.WW.Secrets{,.Abstractions,.Ui} 0.1.2 on the dohertj2-gitea feed; .Cli in-repo (not packed); .Akka replicator deferred (design only)
Reference consumer HistorianGateway — adopted + live-proven (2026-07-16): historian password sourced via ${secret:}, authenticated read against the real wonder historian
Three sister apps Not yet adopted — see per-app current-state + GAPS

Per-project current state

Project Today (baseline) Doc
OtOpcUa (code-verified baseline) current-state/otopcua/CURRENT-STATE.md
MxAccessGateway (code-verified baseline) current-state/mxaccessgw/CURRENT-STATE.md
ScadaBridge (code-verified baseline) current-state/scadabridge/CURRENT-STATE.md

Not applicable as a fourth adopter row but the exemplar: HistorianGateway already consumes the lib — its wiring is the template the three apps follow (see the shared-contract "Consumer wiring" section).