mirror of
https://github.com/shankar0123/certctl.git
synced 2026-06-12 17:38:55 +00:00
This commit is contained in:
@@ -7,7 +7,7 @@
|
||||
--
|
||||
-- All operations use IF NOT EXISTS / IF EXISTS so the migration is
|
||||
-- idempotent — safe to re-run on every certctl-server boot per the
|
||||
-- "Idempotent migrations" architecture decision in CLAUDE.md.
|
||||
-- the project's "Idempotent migrations" architecture decision.
|
||||
--
|
||||
-- Defense in depth: NEVER persist CA private key bytes. The
|
||||
-- key_driver_id column is a reference (filesystem path / KMS key ID
|
||||
|
||||
Reference in New Issue
Block a user