/goal /ultracode-workflows [SEC-3] secrets threat-model + reviewer FAQ (no store code changes) #45
Labels
No labels
bug
discussion
duplicate
enhancement
goal
help wanted
horizon:backlog
horizon:governance
horizon:mvp
invalid
operator-decision
question
roadmap
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Depends on
Reference
open-platform/mitosis#45
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Track/Wave:
SEC-3· Wave G5 · Size SRepos:
mitosis-docsDepends on: SEC-1, SEC-2
Why
A reviewer unfamiliar with the code should be able to state what decrypts what, who sees plaintext and when, and why Vault is deferred — without reading source.
Scope
One doc: what is sealed under the one key and why (sovereignty invariant); the write-only Forgejo-secrets rationale and its implication (platform sees plaintext only transiently in the sync CI job); the dev/prod scope trust boundary; the post-SEC-1 rotation/backup posture; the explicit Vault NON-decision (adds stateful risk without removing the age-key SPOF) plus the trigger to revisit (multi-operator quorum, secret TTLs, dynamic creds).
Acceptance
A reviewer can read the single doc and correctly state what decrypts what, who sees plaintext and when, how rotation/backup work, and why Vault is deferred — without reading source.
Notes
Doc only.
Part of the First Client Deploy → Governance roadmap. The owning agent may recurse into its own subagent team (ultracode workflow) if the task warrants. Honor the seam-serialization: land on a shared seam by rebase, and don't start a seam position until the prior one has merged.