Skip to content

[minor] Restore automatic KMS recovery custody - #30

Merged
libops-agent merged 1 commit into
mainfrom
kms-gcs-recovery
Aug 28, 2026
Merged

[minor] Restore automatic KMS recovery custody#30
libops-agent merged 1 commit into
mainfrom
kms-gcs-recovery

Conversation

@libops-agent

Copy link
Copy Markdown
Contributor

Restore the established automatic recovery flow: Vault returns recovery shares to the initializer, which removes the initial root token, encrypts the recovery bundle with Google KMS, and writes only ciphertext to create-only GCS storage. Optional custodian PGP keys remain supported. X-Admin-Token remains unchanged.

@libops-agent
libops-agent merged commit f82651e into main Aug 28, 2026
5 checks passed
@libops-agent
libops-agent deleted the kms-gcs-recovery branch August 28, 2026 13:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant