noCV
VAULT-104 · Rotate with controlled overlap

Model credential activation and retirement as explicit transitions

Practice briefStoryIntermediate

An operator changes a credential row from RETIRED to ACTIVE to recover an outage. The service resumes using a version that was deliberately revoked after a drill.

Focused work estimate
2h 30m + prerequisites
Priority in the scenario
High
Engineering practice
Lifecycle modeling · Audit trails · Immutable identity

Estimated field mix

  • Security70%
  • Backend30%

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Your next step

Review it, then add it to your workspace.

The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.

Project context

A fictional supplier integration signs incoming webhooks and uses an outbound API credential. Operators currently replace environment values by hand. Build with a deterministic secret-store adapter and fabricated keys only; no live provider account or production credential is part of the exercise.

Setup prerequisites

  • Cryptographic hash APIs
  • HTTP webhook handling
  • Access control

Preceding work

Complete these dependencies, or supply their agreed outputs before taking this ticket.

Acceptance criteria

  • Define staged, active, retiring, retired, and revoked states with named commands.
  • Prevent revoked and retired versions from becoming active again.
  • Audit actor, reason, version references, and transition time without secret material.

Implementation constraints

  • A replacement requires a new credential version; state changes cannot rewrite historical identity.

Verification to include

  • Walk a staged fixture version through activation and retirement.
  • Attempt forbidden reactivation and stale revision updates; assert unchanged history.

Deliverables

  • Credential lifecycle operations and transition matrix

Rollout and recovery

Route fixture operator changes through the commands before removing direct state writes.

Value of the work

For the engineer: Practice credential lifecycle design, overlap windows, authenticated webhooks, and failure recovery without handling real secrets.

For the team: Review whether an engineer can make rotation auditable and fail closed while preserving availability and replay safety.

Evidence boundaries

Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.