Skip to content

Migrate recoverable private archives to per-submission key envelopes #1609

Description

@kim-em

This is post-launch historical migration; new submissions already use per-submission envelopes.

Scope

Complete the exact packet-bound retained-baseline migration, then a separate final-delta packet. Rewrap each recoverable archive data key into the schema-v3 submission/digest-bound envelope without changing ciphertext bytes or stable IDs. Promote the exact audit patch onto current audit main, append validated State, scrub temporary authority/plaintext after each bounded run, and retire migration-only authority after final-delta replay terminality while preserving ordinary v1/v2 unwrap and replay support.

Acceptance criteria

  • every recoverable private archive has a strict submission/digest-bound envelope
  • ciphertext bytes and stable IDs are unchanged
  • orphan/unavailable inventory is explicit and reconciled
  • audit promotion is exact and linear; State/queue/projection validate
  • installed credentials and scratch material are absent after each run
  • after the final delta, migration-only role/environment/key/bootstrap branches are absent while ordinary decrypt/replay remains intact

Out of scope

Exposing the legacy identity, plaintext artifacts/logs, ciphertext rewrites, ID changes, premature key destruction, broad AWS/GitHub authority, or removal of ordinary archive/replay/release roles.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions