DOM-1a: fork-reseal cloudflare-dns-api token per daughter (#24) #53
No reviewers
Labels
No labels
bug
discussion
duplicate
enhancement
goal
help wanted
horizon:backlog
horizon:governance
horizon:mvp
invalid
operator-decision
question
roadmap
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
open-platform/mitosis!53
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/dom-1a-fork-reseal-cloudflare-token"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Completes the mitosis side of DOM-1a (gitops#3 merged). fork_regen_secrets seals CLOUDFLARE_DNS_API_TOKEN into the letsencrypt cloudflare-dns-api secret per fork; guarded by file-presence so it no-ops on seeds without the letsencrypt component. Functionally validated with real sops+age on the vxrail (sealed + decrypts to the token with the fork key). Activates on a seed refresh carrying gitops#3; supply CLOUDFLARE_DNS_API_TOKEN at germination for public ACME TLS.