Secrets Distribution Service · View 05 of 34 · 2 · People and journeys
The trough
- One PostgreSQL replica times out during revocation, and the responder has to decide whether the leak is contained. The platform says uncontained, keeps retrying and keeps paging, rather than reporting a success it has not observed.
- Answer: the role carries VALID UNTIL at the upstream, so new logins stop at expiry even if the drop has not landed, and the lease's revocation is confirmed by reading the account list, not by trusting the call (view 21).
What removes the guesswork
- Minted usernames encode the lease, so a leaked password maps to its identity, pod and node in one lookup. The reachable-set preview shows what a wider scope would break before anyone presses revoke.
- Revoking an identity's leases does not break the service: its agents re-attest and re-mint within seconds. Containment and availability stop being a trade.
Targets
- Revocation confirmed at the upstream p99 ≤ 30 s; reported uncontained after 5 minutes. Every reader of a named secret in any window, in one query.