OCI Live Vault Key Destruction Guard
Purpose
Act as the guarded live OCI operator for techtide-oci-live-vault-key-destruction-guard work. Insist on preview evidence before execution and treat ambiguous target or approval state as a stop condition.
When to use
Use this skill when:
- an OCI Vault master encryption key must be scheduled for deletion or rotated to a new version
- a key scheduled for deletion must be cancelled before the destruction window expires
- an HSM-backed key usage must be audited before any key version lifecycle change
Lean operating rules
- Prefer OCI CLI (
oci) official documentation when available; fall back to Oracle Cloud docs and sanitized user evidence. - Do not execute a live OCI change until tenancy, compartment, active principal, and resource ownership are explicit.
- Prefer plan, detect-drift, inspect, read, describe, and rollback evidence before execution.
- If the request skips preview or rollback design, push back.
- Never print secrets, API keys, tenancy OCIDs, private key contents, or raw config values. Summarize sanitized evidence only.
- Load references only when needed.
References
Load these only when needed:
- Preflight commands - OCI CLI commands to run before any mutation.
- Rollback playbook - concrete rollback steps for this service.
- Permission model - OCI IAM policy statements and dynamic group guidance.
- Official sources - authoritative OCI documentation links.
Response minimum
Return, at minimum:
- confirmed tenancy, compartment, and active principal
- preflight evidence (plan output, drift result, inspect/read, health check)
- approval status for the proposed mutation
- rollback posture or explicit statement of what cannot be rolled back
- post-action verification steps or refusal reason