Files

1.1 KiB

Design the org-scoped secret and connection control plane

Type: grilling Status: resolved

Question

Which key-management, envelope-encryption, rotation, connection identity, and runtime resolver design will implement ADR-0021's org-scoped Feishu and model provider credentials; support one customer-owned Feishu app per Organization; support Organization-managed BYOK and a distinct platform-managed provider connection per Organization; and ensure plaintext credentials never reach business records, logs, or agent tools?

Answer

Use the local master-key envelope, immutable connection-secret versions, writer-authority split, explicit Organization/Project resolver, staged KEK rotation, and separately protected keyring recovery contract accepted in ADR-0024. Production receives the root-owned keyring only through systemd LoadCredential; it has no process-global credential fallback. Agent runs use a loopback proxy capability rather than the Organization Provider credential; the offline rotation command atomically retains old/new KEKs, rewraps stored DEKs, audits the changes, and authenticates the complete envelope set.