Skip to content

[Spec 030] Add rotation acceptance and operator runbook #79

Description

@XnLemon

Parent

#75 (#75)

Depends on

Goal

Prove the complete rotation lifecycle and document operator recovery ownership.

Scope

  • Run a clean acceptance for preparation, partial rollout, activation, mixed Router convergence, credential drain, retirement, restart, planned rollback, and the approved compromise response.
  • Exercise both sample runtimes and root/nested JSON, SSE, cancellation, and exact Release/Trace/Ledger lineage.
  • Verify rejected old/unknown/rebound/retired credentials never reach Runtime logic.
  • Scan public responses, logs, persistence, fixtures, and artifacts for key material, credentials, signatures, and token IDs.
  • Add an operator runbook with preconditions, phase gates, blockers, manual recovery, completion evidence, and incident ownership.

Acceptance criteria

  • Every Spec 030 acceptance scenario maps to a passing contract, integration, or E2E case.
  • The runbook has no retry, alternate endpoint, alternate key source, or degraded-success recovery language.
  • A fresh environment can reproduce both successful rotation and each approved failure outcome.
  • Independent review reports no blocking finding, and Spec/Tasks are converged before closure.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:testingAcceptance, integration, verification, and reviewdocumentationImprovements or additions to documentationenhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions