AIO Launchpadv2 Preview
Secrets
Sync status across the fleet. Values live only in the central Key Vault — never in git, never here.
Central Key Vaults
cont-shared-kv-devconnected
dev environment · source of truth
cont-shared-kv-prodconnected
prod environment · source of truth
Fleet sync status
30
Total
25
Synced
1
Syncing
1
Drift
2
Missing in KV
1
Error
Needs attention
| Site | Secret | Status | Detail |
|---|---|---|---|
| stockholm-assembly-prod | opcua-plc-line-b-password | Drift | KV has a newer version than the cluster |
| stockholm-assembly-prod | mqtt-broker-tls-cert | Error | Forbidden: KV access policy for SecretSync UAMI missing 'get' on 'mqtt-broker-tls-cert' |
| hamburg-assembly-prod | opcua-line-2-username | Missing in KV | Declared but absent from the Key Vault |
| hamburg-assembly-prod | opcua-line-2-password | Missing in KV | Declared but absent from the Key Vault |
Certificate rotation
Rotating a certificate lands a new version in the central Key Vault and rolls it across every site that declares it — as a single fleet patch, gated and tracked like any deployment.
mqtt-broker-tls-cert
on 3 sites: gothenburg-cutting-prod, stockholm-assembly-prod, stockholm-bar-prod
Queues a fleet patch on the Deployments screen. Watch it run there.