Task — engineering-spec@1

"Secrets inventory and rotation runbook"

doneTASK-IMP-041
module improvement · class product · priority p1 · created 2026-07-08 · shipped null
depends on none · blocks none

TASK-IMP-041: Secrets inventory and rotation runbook

Summary

Author a secrets inventory (class, location, owner, blast radius) plus rotate-on-leak steps (R22). Never document secret values.

Problem

The gam updater-key leak showed missing standing process. CI and deploy use many GitHub Actions secrets without a single inventory.

Proposed Solution

docs/runbooks/secrets-inventory-and-rotation.md derived from workflow secret names and known VPS/npm classes.

Alternatives Considered

Success Metrics

Scope

Runbook only. No secret creation/rotation execution in this task.

AI Authorship Disclosure

1. Description (normative)

2. Acceptance criteria

3. Edge cases