ClaraWideProduction secret boundary + config drift QA
v0.12.31 · SECRET BOUNDARY + CONFIG DRIFT

Know which secrets are present without ever storing the secrets.

ClaraWide now records server-side secret requirements, non-reversible fingerprints, configuration snapshots and drift evidence while keeping raw provider credentials out of D1 and browser code. Production baseline changes require stepped-up one-time authorization.

SCHEMA + ATTACK PATHS

Automated configuration-integrity checks

Confirms schema v30, raw-secret exclusion, missing-secret rejection, QA-material rejection, strong-auth baseline control, one-time authorization consumption, drift evidence and immutable snapshots/events.

NOT RUNSchema check has not run yet.
NOT RUNSelf-test has not run yet.
VISIBLE BASELINE FLOW

Snapshot → authorize → baseline → drift

The unsafe step is intentional: ClaraWide should refuse to accept a configuration baseline before the current staff session is stepped up.

READYStart with a QA Security Config Admin session.
APPROVED BASELINE

Known-good configuration fingerprint

No QA baseline accepted yet.

Recent snapshots

No snapshots loaded yet.

IMMUTABLE EVIDENCE

Drift and rejection history

No config events loaded yet.

PRODUCTION GATE — DO NOT FAKE

Production secret/config evidence

These remain open until ClaraWide is actually using an approved production secret store, real provider credentials, scheduled drift monitoring and real incident routing. Checking boxes here is human evidence, not a secret upload form.

Recent config QA runs

No QA runs recorded yet.

Evidence tools

Clearing browser evidence does not rewrite server-owned configuration snapshots, fingerprints or baseline evidence.