Add 2027.1 secret store migration spec
Document path-based PUT /v1/secrets/{id}/secret-store/{ss-id} to re-encrypt a live secret onto another configured backend without changing UUID, ACLs, or consumers.
Secret metadata GET (microversion 1.3) always returns computed secret_store_id/secret_store_ref (null when N/A; HTTP 500 when a live payload cannot be mapped to exactly one catalogue store). Default policy lets admins target any store and members migrate only to the project preferred store.
Implements: blueprint admin-migrate-secret-store
Assisted-by: Cursor Grok 4.5 Change-Id: I6159989aa6b27c0db5ab7dee80836234e9944881 Signed-off-by: Ade Lee alee@redhat.com
版权所有:中国计算机学会技术支持:开源发展技术委员会
京ICP备13000930号-9
京公网安备 11010802047560号