Deploy credential rotation
Rotate TOOLS_PROD_KUBECONFIG_B64 for the complyeaze-tools production deployer.
Checklist:
- Follow docs/deploy-credential-rotation.md from an admin workstation.
- Recreate only the namespace-scoped complyeaze-tools-deployer token Secret.
- Update the GitHub Actions production secret.
- Run pnpm preflight:live with the current deployed digest.
- Confirm deploy-production can still inspect the published image and namespace.
- Revoke the previous token Secret after the new secret is verified.
Deploy credential rotation
Rotate TOOLS_PROD_KUBECONFIG_B64 for the complyeaze-tools production deployer.
Checklist: