Skip to content

chore(secrets): re-seal token from FuzeInfra hand-off (fuzeagent-registration) - #163

Open
izzywdev wants to merge 2 commits into
mainfrom
handoff/fuzeagent-registration-2ad2dff4d1564d63
Open

chore(secrets): re-seal token from FuzeInfra hand-off (fuzeagent-registration)#163
izzywdev wants to merge 2 commits into
mainfrom
handoff/fuzeagent-registration-2ad2dff4d1564d63

Conversation

@izzywdev

Copy link
Copy Markdown
Owner

Automated credential hand-off from izzywdev/FuzeInfra (FuzeInfra#510).

  • Hand-off id: fuzeagent-registration
  • Target scope: fuzeagent/fuzefront-registration, key token (--scope strict)
  • Manifest: deploy/contabo/sealed/fuzefront-registration.yaml (updated with kubeseal --merge-into; all other keys untouched)
  • New credential fingerprint: 2ad2dff4d1564d63
  • Fingerprint currently deployed in fuzeagent: absent

This PR contains ciphertext only. It was produced without any human
or job log ever seeing the plaintext: FuzeInfra read its own Secret
in-cluster, sealed it against the controller cert, and published the
result. Merging it lets Argo CD sync the value into fuzeagent.

…stration)

Automated credential hand-off from izzywdev/FuzeInfra (FuzeInfra#510).

Only the encrypted `token` entry changed; every other key in this
SealedSecret is byte-identical (kubeseal --merge-into).

The value was sealed --scope strict for fuzeagent/fuzefront-registration, so this ciphertext
decrypts nowhere else. No plaintext was logged, committed, or handled
by a human at any point.

Credential fingerprint (sha256[:16]): 2ad2dff4d1564d63
Previously deployed fingerprint:      absent
@github-actions
github-actions Bot enabled auto-merge (squash) August 21, 2026 02:02
@claude claude Bot added the auto-merge label Aug 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant