Skip to content

Prove Kubernetes TLS identity rotation and rollback under load - #579

Merged
RicheyWorks merged 1 commit into
mainfrom
codex/kubernetes-tls-rotation-proof
Aug 19, 2026
Merged

Prove Kubernetes TLS identity rotation and rollback under load#579
RicheyWorks merged 1 commit into
mainfrom
codex/kubernetes-tls-rotation-proof

Conversation

@RicheyWorks

Copy link
Copy Markdown
Owner

Outcome

  • prove inbound TLS identity rotation and rollback with two independently rooted immutable Kubernetes TLS Secrets
  • keep continuous dual-CA traffic running while the Deployment Secret pointer changes in both directions
  • require trust-boundary changes, served-leaf fingerprint changes, full pod UID turnover, unchanged image IDs, two-zone readiness, and per-replica/backend traffic
  • advance the live topology profile to schema v5 and reject 52 unsafe profiles

Verification

  • focused Kubernetes contract tests: 4 passed
  • staged shell contract: 52 unsafe profiles rejected
  • full Maven test suite: 2,327 passed
  • Maven package with tests skipped: passed

The live disposable kind proof is delegated to exact-head Linux CI because Docker Desktop is unavailable locally.

@RicheyWorks
RicheyWorks merged commit 41b6b91 into main Aug 19, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant