CR-2026-02-25: Wazuh Credential Rotation — Risk & Comms
Key Lessons
| Issue | Mitigation |
|---|---|
K8s secret != OpenSearch password |
Must run |
Hardcoded secrets in config files |
Use environment variables: |
Flat gopass structure |
Use resource-based paths: |
No pre/post validation |
Always test access BEFORE and AFTER rotation |