Skip to content

feat(credentials): add fail-closed Postgres environment sync - #10

Open
kaanyagci wants to merge 17 commits into
feat/brio-staging-pocfrom
chore/postgres-credential-sync
Open

feat(credentials): add fail-closed Postgres environment sync#10
kaanyagci wants to merge 17 commits into
feat/brio-staging-pocfrom
chore/postgres-credential-sync

Conversation

@kaanyagci

@kaanyagci kaanyagci commented Sep 5, 2026

Copy link
Copy Markdown
Member

Summary

  • add a machine-readable Proton Pass to protected GitHub environment inventory for all six PostgreSQL environments
  • add a fail-closed names-only audit and one-environment stdin-only sync helper
  • reject repository secrets, unmanaged names, wrong public repository identity, and non-exact-main environment policies
  • separate public policy variables from host-only/controller credentials
  • correct the Brio PKI and database-password destination matrix
  • add adversarial tests and run them from the complete CI entrypoint

Verification

  • ./scripts/run-ci.sh
  • ./scripts/sync-github-environments.sh --check --environment canary (names-only; expected to report the not-yet-created shared deployment item and two legacy canary names)

No credential values were read. No Proton Pass item or GitHub secret, variable, environment, or policy was mutated.

@kaanyagci
kaanyagci requested a review from idilsaglam September 5, 2026 04:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant