The secret the vault provides a module is the credential of the consumer↔vault pair, and so is every credential a provider grants; sealing only own secrets to the operator left exactly those unrecoverable. Same column, same call; the export and `secret recover` address a pair by consumer node, module and the provision's name, and say which kind each entry is.
11 lines
560 B
SQL
11 lines
560 B
SQL
-- The same second seal for a pair credential (novox/hq ADR 0085, amended).
|
|
--
|
|
-- 0023 gave a module's own secrets an operator-sealed copy. A secret the vault provides to a module
|
|
-- is not an own secret -- it is the credential of the consumer-vault pair -- and so were the
|
|
-- credentials every provider grants. Without this, a vault-provided password could be rotated and
|
|
-- audited but not recovered, which is a vault that keeps everything except what it was for.
|
|
|
|
alter table secret
|
|
add column operator_sealed text,
|
|
add column operator_key text;
|