Credential Drift And Repair
Credential repair must follow the public-key grant contract in the feed.
- Use per-device or per-session private keys at the stable local contract path.
- Register or transmit public keys only; never copy private keys between devices, agents, or sessions.
- Do not silently replace a key to make one route work.
- If Pi, relik-vps, Forgejo, repo access, feed metadata, key titles, or fingerprints disagree, treat it as credential drift until reconciled.
- Record credential repairs in the Forgejo source-of-truth path that owns the contract, feed, or operating procedure.
- Feed/source changes must follow the publish workflow in
PILLARS/STONES/KEYS/feed/README.md.