Postmaster DID ceremony + KMS + hosted spaces-PDS
closedGoal
Stand up the postmaster identity (ADR-0006 D8): the configurable DID that serves as space authority and authors all sovrn records.
Tasks
- Postmaster DID creation ceremony: dedicated
did:plc:*(hosted) or operator DID (self-hosted);#atproto_spaceverification key +#atproto_space_hostservice entry in the DID doc. - Keys in KMS (separate from OAuth attestation + OIDC keys); rotation procedure documented (note: rotating the postmaster DID re-keys every space URI — effectively permanent).
- Config: postmaster DID + credentials supplied to
sovrndat startup (internal/postmaster). - Hosted spaces-PDS: develop against atproto-crates reference PDS (docs/06 §4); wire the postmaster’s PDS as space host.
Depends on: PDS selection/dev harness (docs/06, tracker f98ccdc C1).
Blocks: spaceproj publisher, reconciler.
Basis: docs/adr/0006-data-placement-and-space-topology.md, docs/04 §2–§3, docs/06 §5.
1 Comment
Superseded by epic 516fcde. Delivered: per-domain postmaster identity (postmaster.at.) created by the domain saga. Obsolete: the single configurable postmaster DID (replaced by ADR-0009 D32 per-domain postmasters; config postmaster.did is unused). Deferred to Spaces Stage B: KMS per authority, #atproto_space key + #atproto_space_host service entry, hosted spaces-PDS. Closing.