Secrets rotation tool should check for the RotationComplete tag in primary state
Open
Central-EngSys
- Dominant language
- C#
- Stars
- 135
- Forks
- 260
- Avg merge
- 3d 1h
- Merged PRs (30d)
- 143
Description
To accommodate recovery from failed rotation, the plan should not consider a rotation as current/unexpired if the secret doesn't have a RotationComplete=true tag
Contributor guide
Research direction
Inspect the secrets rotation tool's plan logic, focusing on how primary state determines whether a rotation is current or unexpired. Verify the behavior against recovery from failed rotation and the RotationComplete=true tag; done means rotations without that tag are not treated as current or unexpired.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- csharp
- Domain
- security, tooling
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100