Security: leaked secrets cleanup + rotation (tracking) #1
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Security: leaked secrets cleanup + rotation (tracking)
Classification: security — secret VALUES are intentionally NOT in this issue body because
d-bis/proxmoxis a public Gitea repo. The authoritative inventory (with categorized values and per-file remediation plan) lives out-of-repo under operator control — see "Artefacts" below.Owner: @nsatoshi2007
Coordinating agent: Devin session 8d9743d4
Summary
A Phase-0 read-only scan of
masteratd63efcb3and of the pinnedsmom-dbis-138submodule identified tracked files that contain:Proxmox repo
cb47cce0(2026-01-06),fbda1b4b(2026-02-12),bea1903a(2026-02-21) — all onmastersmom-dbis-138 submodule (pinned at
07d9ce4876)scripts/set-private-key.shterraform/phases/phase1/.env.chain138terraform/phases/phase1/.env.mainnetPhased remediation (tracking checklist)
smom-dbis-138,phoenix-deploy-api,mission-controlphoenix-deploy-api,mission-control, andproxmox/scripts/deployment/proxmox(git filter-repo), coordinated force-push + Gitea admin branch-protection updatesmom-dbis-138for the 3 files abovegit@vs HTTPS).github/workflows/vs.gitea/workflows/) with runner-readiness checkreports/,output/,scripts/archive/)Artefacts (operator-only, out-of-repo)
Held by @nsatoshi2007:
LEAKED_SECRETS_INVENTORY.md— per-file per-category remediation mapsecrets.tsv— line-level snippets (contains plaintext; do not paste into this issue)scan-secrets.sh— reproducible scan toolproxmox-cleanup-plan.md— 6-phase plan with approval gatesRules of engagement
proxmoxorsmom-dbis-138until Phase 1 (rotation) is verified complete on the live systems.