noCV
VAULT-102 · Make credential use explicit

Move secret lookup behind a version-aware provider

Practice briefTaskIntermediate

API and worker read process environment independently and cannot report which credential version they are using. The test suite also embeds key values in request snapshots.

Focused work estimate
2h 30m + prerequisites
Priority in the scenario
High
Engineering practice
Provider interfaces · Secret handling · Fail-closed configuration

Estimated field mix

  • Security60%
  • Backend40%

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Pattern topics

  • Ports and AdaptersApply

    Separate version-aware secret lookup from provider details so the deterministic adapter and an unavailable provider obey the same fail-closed contract.

Your next step

Review it, then add it to your workspace.

The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.

Project context

A fictional supplier integration signs incoming webhooks and uses an outbound API credential. Operators currently replace environment values by hand. Build with a deterministic secret-store adapter and fabricated keys only; no live provider account or production credential is part of the exercise.

Setup prerequisites

  • Cryptographic hash APIs
  • HTTP webhook handling
  • Access control

Preceding work

Complete these dependencies, or supply their agreed outputs before taking this ticket.

Acceptance criteria

  • Define lookup by logical credential name and permitted version reference.
  • Return a non-secret version identity separately from sensitive material.
  • Use a deterministic fixture adapter and fail closed when no provider is configured.

Implementation constraints

  • Keep secret material out of serialized DTOs and snapshot assertions.

Verification to include

  • Resolve a known synthetic version for an authorized consumer.
  • Reject an unknown version, unauthorized consumer, and absent provider without fallback secrets.

Deliverables

  • Secret provider contract and deterministic adapter

Rollout and recovery

Migrate one synthetic consumer at a time; keep configuration rollback limited to the fixture provider.

Value of the work

For the engineer: Practice credential lifecycle design, overlap windows, authenticated webhooks, and failure recovery without handling real secrets.

For the team: Review whether an engineer can make rotation auditable and fail closed while preserving availability and replay safety.

Evidence boundaries

Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.