security: retire exposed Zot storage identity #67
Loading…
Reference in a new issue
No description provided.
Delete branch "security/retire-zot-storage-identity"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Complete the three-phase Zot MinIO credential rotation after the v2 identity passed scope proof, bucket initialization, a full Zot restart, and public immutable-manifest reads. Stop generating or converging the exposed v1 identity. Add an idempotent retirement Job that removes user
zotand fails if authority remains.Tests: targeted rotation contract, full seanfarm checks, and tenantbucket render pass.