Skip to content

[þing-01][OPERATOR] Key issuance (three tiers), test-project decision, rotation design (O1) #9

Description

@Polichinel

Context: the platform's Appwrite-seam identity/config was folk knowledge — one unowned laptop .env as origin, one all-powerful key, and misconfiguration that silently succeeds into phantom storage. The ratified verdict fixes this via one contract ADR (PLATFORM-001), one owned coordinates registry file, declared classification, three credential tiers, and raise-by-default failure semantics.

Operator: Simon Polichinel von der Maase (named at ratification). The operator's duties from the verdict:

  1. Issue the split keys in the Appwrite console per D4: a read key, a write-object key, and a provision key handed to no long-running process. Record names + scopes in the registry (A3); never values.
  2. Decide the test project: create a non-production Appwrite project, or leave the "prod integration tests forbidden" rule standing. This gates the D5 provisioning-path drill and the A7 trigger.
  3. Own rotation — and drive O1: the secret-value rotation/propagation design (Tier-2 open item; the registry moves coordinates, but no mechanism distributes a rotated key VALUE to process envs). Until designed, rotation is manual and operator-coordinated.
    Filed here because the seam home tracks the seam's open items; the assignee is a human, not the repo.

Part of þing-01 — the platform Identity/Secrets/Configuration verdict, ratified as amended
2026-07-28 (sign-off: Simon Polichinel von der Maase, who is also the named operator).
Canonical record (local): views_platform/þingit/01_identity_secrets_config/orð_dómr.md
as amended by dómr_endurmat.md; plain-language summary in final_decision.md.

🤖 Generated with Claude Code

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions