noCV
VAULT-109 · Recover and audit

Make emergency revocation reach cached consumers

Practice briefBugExpert

An operator revokes a synthetic compromised key, but a worker's indefinite cache continues signing requests with it. Another worker refreshes and succeeds, hiding the inconsistent state.

Focused work estimate
5h + prerequisites
Priority in the scenario
High
Engineering practice
Revocation consistency · Cache lifetimes · Failure modes · Security operations

Estimated field mix

  • Security60%
  • Distributed systems40%

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Your next step

Review it, then add it to your workspace.

The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.

Project context

A fictional supplier integration signs incoming webhooks and uses an outbound API credential. Operators currently replace environment values by hand. Build with a deterministic secret-store adapter and fabricated keys only; no live provider account or production credential is part of the exercise.

Setup prerequisites

  • Cryptographic hash APIs
  • HTTP webhook handling
  • Access control

Preceding work

Complete these dependencies, or supply their agreed outputs before taking this ticket.

Acceptance criteria

  • Bound cache lifetime and propagate credential authority revisions to all consumers.
  • Prevent use after the declared revocation deadline, including during provider outage.
  • Audit revocation convergence using version references and consumer acknowledgements only.

Implementation constraints

  • Cached availability cannot override explicit revocation; define the exercise's maximum revocation delay.

Verification to include

  • Revoke a cached fixture key across two consumers and measure convergence.
  • Drop one invalidation notification and disable lookup; verify use stops at the deadline.

Deliverables

  • Revocation propagation design and failure-interleaving tests

Rollout and recovery

Enforce bounded caching before testing emergency revoke; pause outbound work when authority cannot be refreshed safely.

Value of the work

For the engineer: Practice credential lifecycle design, overlap windows, authenticated webhooks, and failure recovery without handling real secrets.

For the team: Review whether an engineer can make rotation auditable and fail closed while preserving availability and replay safety.

Evidence boundaries

Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.