Skip to content

docs(designs): add secrets and pki design#13

Merged
jmgilman merged 1 commit intomasterfrom
session-026/secrets-design
Apr 21, 2026
Merged

docs(designs): add secrets and pki design#13
jmgilman merged 1 commit intomasterfrom
session-026/secrets-design

Conversation

@jmgilman
Copy link
Copy Markdown
Contributor

Summary

  • add a Secrets and PKI design covering AWS-authoritative SOPS bootstrap, GitHub App repo access, scoped KMS decryption, and per-cluster Vault
  • document public HTTP TLS through Let's Encrypt/Route 53 DNS-01 and internal PKI through KMS-rooted per-cluster Vault CAs
  • call out step-ca retirement, root CA rebootstrap into the current lab AWS account, and implementation slices

Validation

  • moon run docs:check
  • npm run typecheck
  • npm run build

@jmgilman jmgilman merged commit e9c3379 into master Apr 21, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant