Skip to content

Replace retired connection-owned OpenTofu state profiles with vault-owned authority #239

Description

@adrianwebb

Objective

Restore hosted state backend/encryption authority through the Vault model, not Cloudflare service forms. SDK rc92 intentionally excludes retired s3-state-session/opentofu-state-encryption credential profiles; API hosted-provider-authority still assumes those connection-owned profiles.

Boundary

Do not restore those service fields or silently broaden object-storage authority. Hosted apply remains fail-closed until a vault-owned state authority resolver binds exact team/deployment/environment/backend digest.

Acceptance

Positive vault-scoped state backend/encryption cases; cross-team/ref/digest denial; no provider credential substitution; existing-key identity retained; audited short-lived custody session; OpenTofu state isolation and rollback.

Evidence

API PR #236 Actions run 34079118156 exposed stale positive tests. Provider credentials pass; retired profile paths are rejected. This is a production gate, not accepted deployment behavior.

Dependencies and rollback

Shared Vault authorization contracts and Deployment OpenTofu resolver. Keep current fail-closed behavior until full replacement accepted.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions