noCV
VAULT-108 · Recover and audit

Rotate outbound credentials without retrying an ambiguous write twice

Practice briefTaskExpert

An outbound supplier update times out during credential rotation. The worker retries with the new key and a fresh request ID, creating the same supplier instruction twice.

Focused work estimate
5h + prerequisites
Priority in the scenario
High
Engineering practice
Credential rotation · Ambiguous outcomes · Idempotent integrations · Recovery protocols

Estimated field mix

  • Integrations40%
  • Security30%
  • Distributed systems30%

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Your next step

Review it, then add it to your workspace.

The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.

Project context

A fictional supplier integration signs incoming webhooks and uses an outbound API credential. Operators currently replace environment values by hand. Build with a deterministic secret-store adapter and fabricated keys only; no live provider account or production credential is part of the exercise.

Setup prerequisites

  • Cryptographic hash APIs
  • HTTP webhook handling
  • Access control

Preceding work

Complete these dependencies, or supply their agreed outputs before taking this ticket.

Acceptance criteria

  • Keep one operation identity across credential version changes and retries.
  • Distinguish authentication rejection from an unknown remote commit outcome.
  • Use the fixture supplier's idempotency/status contract before resending an ambiguous write.

Implementation constraints

  • Do not assume changing credentials resets business idempotency or proves a timed-out request failed.

Verification to include

  • Rotate after a confirmed authentication failure and complete one logical operation.
  • Simulate remote commit followed by timeout; reconcile through status lookup and assert no duplicate instruction.

Deliverables

  • Outbound rotation retry protocol and ambiguous-outcome reproduction

Rollout and recovery

Verify against the deterministic supplier adapter before switching fixture consumers; pause ambiguous writes if status lookup fails.

Value of the work

For the engineer: Practice credential lifecycle design, overlap windows, authenticated webhooks, and failure recovery without handling real secrets.

For the team: Review whether an engineer can make rotation auditable and fail closed while preserving availability and replay safety.

Evidence boundaries

Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.