Secrets Distribution Service · View 04 of 34 · 2 · People and journeys
The trough
- A hotfix image pushed outside the delivery pipeline has a digest the identity entry does not know, so the pod is refused a credential. This is the design working, and it will not feel like it at 02:00.
- Answer: the refusal names the missing selector and the pipeline that would have registered it (view 16). The break-glass path for a digest is the pipeline itself, run with approval waived for a declared incident, never an identity created by hand.
What makes the rest quiet
- The registry lint rejects a grant with no owner, a wildcard or a mismatched environment before review. The pull request shows the identity's complete reachable set, so the reviewer approves a list, not a policy language.
- Renewal is the agent's problem. The team's code reads a local socket and never sees an address, a token or a schedule.
Targets
- Credential available before main() runs: attestation p99 ≤ 400 ms, mint p99 ≤ 500 ms. Second approval for production custodial grants within four working hours.