security: stage rotated Zot storage identity #63
Loading…
Reference in a new issue
No description provided.
Delete branch "security/rotate-zot-storage-identity"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Create a second bucket-scoped MinIO identity for Zot and prove it can read only the zot bucket. Keep the current registry consumer unchanged until the new identity is live.
This is phase 1 of a no-gap credential rotation after Zot wrote the old key to its info log. The full seanfarm guard suite passes.