secrets-management

ARCHIVED

"secret management has to be easier than this - what are best practices in the software industry?" "super tired of having to hunt down keys again and again — this was supposed to be the point of a shared monorepo"

STAGES

  1. proposal08-21
  2. requirements08-21
  3. design08-21
  4. tasks08-21
  5. build—
  6. archived08-21

CAPABILITIES — 2 IN ONE CHANGE

  • secret-references3 requirements
  • secret-sync2 requirements

OUTCOMES — AND HOW EACH IS MEASURED

  • ✓1.1Printing the env file leaks nothingnot stated
  • ✓1.2A dedicated vault holds the hub's credentialsnot stated
  • ✓1.3Dev server starts with working credentialsnot stated
  • ✓1.4A broken CLI integration fails loudly, not silentlynot stated
  • ✓1.5An agent attempt to print the env file is refusednot stated
  • ✓1.6Legitimate key-name inspection still worksnot stated
  • ✓1.7Sync reports drift and corrects itnot stated
  • ✓1.8Sync previews before it writesnot stated
  • ✓1.9Orphaned secrets are surfaced, not silently keptnot stated
  • ✓1.10Rotating a key with no prior contextnot stated
  • ✓1.11The runbook records vendor differences that caused past mistakesnot stated

WHAT HAPPENED

  1. ARCHIVED

    proposal and specs and design and tasks and archive landed

    2026-08-21 · 1 pull request
    • #397docs(openspec): archive secrets-management

History read from a manifest built at 2026-09-30 (09e7bcc).

1 pull request, found by commits touching the change folder