rotate: 6 service-API drivers (mongo, npm, gcp, twilio, flyio, k8s)
Each driver is real-service code only (no test awareness; tests inject just an HTTPClient/Bin), following the established patterns: - mongo: in-place changeUserPassword over the old connection; no secret on argv (host/db on the URI, both passwords on stdin, output scrubbed). - npm: create token -> /-/whoami -> delete-by-key; blob records the key. - gcp: service-account KEY rotation; mints an RS256 JWT signed with the SA's own private key (crypto/rsa, stdlib) to self-auth the IAM create/verify/delete. - twilio: API Key create -> get -> delete, Basic auth (KeySid/secret). - flyio: GraphQL — a managing token mints/deletes the rotated deploy token. - k8s: create a service-account-token Secret, await the populated token, verify against the SA, delete the old Secret (invalidates the old token). All 6 register their honest proof level (MOCK-ONLY) in proofs.go + ROTATION-PROOFS.md; mongo/npm/k8s are LIVE-VM candidates pending real-target VM POCs. Emulators enforce credential validity (gcp verifies the JWT signature), tests assert Verify(old) fails after revoke + a secret-leak canary. Full suite: 103 green, -race clean on rotate/sink/vault. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -63,6 +63,12 @@ var proofLevels = map[string]ProofLevel{
|
||||
"cloudflare": ProofMockOnly, // httptest emulator; no self-host
|
||||
"ghactions": ProofMockOnly, // httptest emulator; no self-host
|
||||
"gitlab": ProofMockOnly, // httptest emulator; GitLab CE too heavy for the VM
|
||||
"mongo": ProofMockOnly, // fake-mongosh stub; real-MongoDB VM POC not yet run
|
||||
"npm": ProofMockOnly, // httptest emulator; real registry never hit
|
||||
"gcp": ProofMockOnly, // httptest emulator (real RS256 JWT signing); no self-host
|
||||
"twilio": ProofMockOnly, // httptest emulator; no self-host
|
||||
"flyio": ProofMockOnly, // httptest GraphQL emulator; no self-host
|
||||
"k8s": ProofMockOnly, // httptest apiserver emulator; real k3s POC not yet run
|
||||
}
|
||||
|
||||
// ProofLevelOf returns the recorded proof level for a driver name. Unknown or
|
||||
|
||||
Reference in New Issue
Block a user