Azure / Azure/azure-sdk-tools

Secrets rotation tool should check for the RotationComplete tag in primary state

Open
#5,649 0 comments 0 reactions 0 assignees View on GitHub
Central-EngSys
Dominant language
C#
Stars
135
Forks
260
Avg merge
3d 1h
Merged PRs (30d)
143

Description

To accommodate recovery from failed rotation, the plan should not consider a rotation as current/unexpired if the secret doesn't have a RotationComplete=true tag

Contributor guide

Open the contributing guide

Research direction

Inspect the secrets rotation tool's plan logic, focusing on how primary state determines whether a rotation is current or unexpired. Verify the behavior against recovery from failed rotation and the RotationComplete=true tag; done means rotations without that tag are not treated as current or unexpired.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp
Domain
security, tooling
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.