ReferenceSecrets
Postgres CA certificate
TLS verify-full root cert.
Secret: Postgres CA certificate
Purpose: TLS verify-full root cert.
Source: Static file or build artifact
Rotation runbook: /docs/operate/cert-rotation
How it's used
Loaded at container startup. Failure to read the secret usually causes a fatal startup error.
How to rotate
See the linked runbook above. Most secrets have a documented zero-downtime rotation procedure.
Related
- Security — Secrets management — full inventory.
- Operate — Secrets audit — quarterly cadence.