docs(handbook): setting up key custody — all three modes (#112 follow-up) #207
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "docs-openbao-custody"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Adds a customer-facing "Setting up key custody" section to
docs/handbook/encryption.md, right after the conceptual custody-modes list and before the recovery-identity section. Written for someone self-deploying Cairn, covering the operational setup for all three modes:<mount>/{data,metadata}/<prefix>/*, minting a periodic token, config fields, lazy per-user/per-space paths, and OpenBao-must-be-unsealed as a hard dependency. Distilled from the #112 e2e that just landed.instanceSeedmulti-instance note.Product-neutral (generic
<keycloak-host>,<openbao-host>,<mount>placeholders — no lab hostnames/IPs), per the handbook rules. Existing content untouched; the section was spliced in by a self-removed one-shot workflow. Docs only.