Overview
Two AWS accounts hold secrets
Rotation & Rollout
RDS-managed password rotation + secrets naming convention
OpenBao
Status: living document, in progress. This is the standalone reference for OpenBao's role as both a secret consumer (its own TLS cert, its SaaS admin token) and a secret store in its own right (per-tenant namespaces, agent mTLS PKI issuance). The openbao-init sidecar in cogrion-gitops's openbao.values.yaml only initializes OpenBao, creates the namespace, and mints a saas-admin token — everything else here is done by hand, the same way it was originally done for prod-sgp.