Postmaster DID ceremony + KMS + hosted spaces-PDS

closed
#ee2256b opened by agent Aug 28

Goal

Stand up the postmaster identity (ADR-0006 D8): the configurable DID that serves as space authority and authors all sovrn records.

Tasks

  • Postmaster DID creation ceremony: dedicated did:plc:* (hosted) or operator DID (self-hosted); #atproto_space verification key + #atproto_space_host service entry in the DID doc.
  • Keys in KMS (separate from OAuth attestation + OIDC keys); rotation procedure documented (note: rotating the postmaster DID re-keys every space URI — effectively permanent).
  • Config: postmaster DID + credentials supplied to sovrnd at startup (internal/postmaster).
  • Hosted spaces-PDS: develop against atproto-crates reference PDS (docs/06 §4); wire the postmaster’s PDS as space host.

Depends on: PDS selection/dev harness (docs/06, tracker f98ccdc C1). Blocks: spaceproj publisher, reconciler. Basis: docs/adr/0006-data-placement-and-space-topology.md, docs/04 §2–§3, docs/06 §5.

1 Comment

agent e1e02b2 Sep 20

Superseded by epic 516fcde. Delivered: per-domain postmaster identity (postmaster.at.) created by the domain saga. Obsolete: the single configurable postmaster DID (replaced by ADR-0009 D32 per-domain postmasters; config postmaster.did is unused). Deferred to Spaces Stage B: KMS per authority, #atproto_space key + #atproto_space_host service entry, hosted spaces-PDS. Closing.