Skip to content

feat(credentials): add fail-closed Postgres environment sync - #10

Closed
kaanyagci wants to merge 17 commits into
feat/brio-staging-pocfrom
chore/postgres-credential-sync
Closed

kaanyagci wants to merge 17 commits into
feat/brio-staging-pocfrom
chore/postgres-credential-sync

Conversation

@kaanyagci

@kaanyagci kaanyagci commented Sep 5, 2026

Copy link
Copy Markdown
Member

Summary

  • add a machine-readable Proton Pass to protected GitHub environment inventory for all six PostgreSQL environments
  • add a fail-closed names-only audit and one-environment stdin-only sync helper
  • reject repository secrets, unmanaged names, wrong public repository identity, and non-exact-main environment policies
  • separate public policy variables from host-only/controller credentials
  • correct the Brio PKI and database-password destination matrix
  • add adversarial tests and run them from the complete CI entrypoint

Verification

  • ./scripts/run-ci.sh
  • ./scripts/sync-github-environments.sh --check --environment canary (names-only; expected to report the not-yet-created shared deployment item and two legacy canary names)

No credential values were read. No Proton Pass item or GitHub secret, variable, environment, or policy was mutated.

@kaanyagci
kaanyagci requested a review from idilsaglam September 5, 2026 04:46
@kaanyagci

Copy link
Copy Markdown
Member Author

Closing as already incorporated. Every file changed by this PR exactly matches its version in main commit ad93c2c, which remains an ancestor of current main (7 files verified). Current staging contains subsequent fixes and passed signed live runtime controls and Brio release acceptance. The branch is retained; no code or runtime is removed.

@kaanyagci kaanyagci closed this Sep 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant