secrets-management
ARCHIVED"secret management has to be easier than this - what are best practices in the software industry?" "super tired of having to hunt down keys again and again — this was supposed to be the point of a shared monorepo"
STAGES
- proposal08-21
- requirements08-21
- design08-21
- tasks08-21
- build—
- archived08-21
CAPABILITIES — 2 IN ONE CHANGE
- secret-references3 requirements
- secret-sync2 requirements
OUTCOMES — AND HOW EACH IS MEASURED
- ✓1.1Printing the env file leaks nothingnot stated
- ✓1.2A dedicated vault holds the hub's credentialsnot stated
- ✓1.3Dev server starts with working credentialsnot stated
- ✓1.4A broken CLI integration fails loudly, not silentlynot stated
- ✓1.5An agent attempt to print the env file is refusednot stated
- ✓1.6Legitimate key-name inspection still worksnot stated
- ✓1.7Sync reports drift and corrects itnot stated
- ✓1.8Sync previews before it writesnot stated
- ✓1.9Orphaned secrets are surfaced, not silently keptnot stated
- ✓1.10Rotating a key with no prior contextnot stated
- ✓1.11The runbook records vendor differences that caused past mistakesnot stated
WHAT HAPPENED
- ARCHIVED
proposal and specs and design and tasks and archive landed
2026-08-21 · 1 pull request- #397docs(openspec): archive secrets-management
History read from a manifest built at 2026-09-30 (09e7bcc).
1 pull request, found by commits touching the change folder