Security

Credential inventory and rotation

What exists, who holds it, and what is overdue. Several of these are personal credentials doing organisational work, which is the single largest concentration of risk on this page.

Scope HQ, AWS, Azure, GitHubVerified 8 October 2026Review Quarterly

1Pending rotation

Each of these is known to be exposed, shared, or past the point where it should have been replaced. Listed with the reason, because a rotation list without reasons gets deferred indefinitely.

CredentialWhyBlast radius if abused
itadmin host passwordTyped into a shell on prod-k8s-master-01 on 7 October and recorded in history and transcriptsSSH to all six nodes
GitHub PAT used for the initial pushExposed in working transcripts during SeptemberRepository write
Postgres superuserExposed in working transcripts; should be disabled outright with enableSuperuserAccess: false once nothing needs itEvery production database
dbadmin roleExposed in working transcriptsCreate role, create database
Clear the shell history as well as the password

Rotating a password that is still sitting in ~/.bash_history on a production node only solves half the problem. Check for it, delete the entry, and write the file back — on every node where it may have been typed.


2Personal credentials doing organisational work

This is the pattern most worth fixing, because it does not fail until someone leaves — and then it fails everywhere at once.

CredentialUsed byWhat breaks when it goes
GHCR token on tman-dcbarAround 39 Image Updater entriesImage updates stop estate-wide, silently
GHCR token on timramlogandcbarHelpDesk image pullsHelpDesk pods cannot pull images
Per-namespace ghcr-pull-secretEvery application namespaceThat application cannot pull

The deployment generator reinforces this: its setup commands say --docker-username=<your-gh-username>, so every person who follows the documented process adds another personal dependency. Replacing those with an organisation-owned machine account, and changing the generator’s placeholder, fixes the cause rather than the instances.

Image pull failures are not loud

A token that expires does not alert. The first symptom is a deployment that does not roll, or a pod that cannot start after an unrelated restart, days or weeks later. There is nothing currently watching for it.


3Dated credentials

Things that will expire on a known date, whether or not anyone is watching. These feed the renewal reminders in the Vendors section.

ItemExpiresEffect
*.dcbar.org wildcard certificate27 November 2026TLS fails on every production hostname
app-kv-reader service principal secretTwo years from creation — date not recordedPods cannot mount secrets and will not start
GHCR personal access tokensNot recordedImage pulls and updates fail
SendGrid API keyNot recordedAll alerting stops, silently

Three of those four have no recorded date. That is the actual finding: the estate has at least four credentials with hard expiries and knows the date of one of them.


4Database roles

From the app-db cluster on 8 October 2026. Application roles follow <database>_user and own their own database; the rest are platform roles.

RoleAttributesPurpose
postgresSuperuser, replication, bypass RLSPlatform. Candidate for disabling.
dbadminCreate role, create DBAdministration
streaming_replicaReplicationCloudNativePG replication
cnpg_pooler_pgbouncer—PgBouncer authentication
cnpg_metrics_exporter—Metrics
watchdog—Database monitoring CronJobs
appuser—Owns appdb and crm-production
Seven *_user rolesCreate role, create DBOne per application database
Application roles have more privilege than they need

Most *_user roles carry Create role and Create DB. An application compromised through SQL injection could then create roles and databases rather than only reading its own. Nothing here requires those attributes at runtime; they are an artefact of how the roles were created.


5When someone leaves

Until the personal credentials above are replaced, an IT leaver is an infrastructure event. The list to work through:

The shape of that list is itself the argument for the fix: with organisational credentials, most of these lines disappear.