This is post-launch historical migration; new submissions already use per-submission envelopes.
Scope
Complete the exact packet-bound retained-baseline migration, then a separate final-delta packet. Rewrap each recoverable archive data key into the schema-v3 submission/digest-bound envelope without changing ciphertext bytes or stable IDs. Promote the exact audit patch onto current audit main, append validated State, scrub temporary authority/plaintext after each bounded run, and retire migration-only authority after final-delta replay terminality while preserving ordinary v1/v2 unwrap and replay support.
Acceptance criteria
- every recoverable private archive has a strict submission/digest-bound envelope
- ciphertext bytes and stable IDs are unchanged
- orphan/unavailable inventory is explicit and reconciled
- audit promotion is exact and linear; State/queue/projection validate
- installed credentials and scratch material are absent after each run
- after the final delta, migration-only role/environment/key/bootstrap branches are absent while ordinary decrypt/replay remains intact
Out of scope
Exposing the legacy identity, plaintext artifacts/logs, ciphertext rewrites, ID changes, premature key destruction, broad AWS/GitHub authority, or removal of ordinary archive/replay/release roles.
This is post-launch historical migration; new submissions already use per-submission envelopes.
Scope
Complete the exact packet-bound retained-baseline migration, then a separate final-delta packet. Rewrap each recoverable archive data key into the schema-v3 submission/digest-bound envelope without changing ciphertext bytes or stable IDs. Promote the exact audit patch onto current audit main, append validated State, scrub temporary authority/plaintext after each bounded run, and retire migration-only authority after final-delta replay terminality while preserving ordinary v1/v2 unwrap and replay support.
Acceptance criteria
Out of scope
Exposing the legacy identity, plaintext artifacts/logs, ciphertext rewrites, ID changes, premature key destruction, broad AWS/GitHub authority, or removal of ordinary archive/replay/release roles.