9bac2685cb
workflows-src/rotate-aws-key.yml — daily cron (0 0 * * *) + workflow_dispatch, wraps scripts/rotate_spike_key.sh (uses NOVA_AWS_* static-key auth to IAM- rotate the nova-spike-runner key; uploads the new key to the consumer's Actions secret store; idempotent — deactivates the old key only after the new propagates, verified by a post-PUT GET). Synced to .github + .gitea. v0.2 scope: the mechanism exists (SPEC §5.9 — exists-not-ran); the v0.2 deploy uses the currently-active key. Documented in ARCHITECTURE.md §12.9. The synced workflow file is forge-agnostic (REQ-230): forge base URL / owner / consumer repo come from repository secrets (NOVA_FORGE_*, NOVA_CONSUMER_REPO), not literals. rotate_spike_key.sh reads NOVA_FORGE_* with NOVA_GITEA_* backward-compat fallback. sync_workflows.py PAIRS extended to include rotate-aws-key.yml (was hardcoded to 3 pairs). ---ci--- project: acdl phase: 3 milestone: v1.26 status: execute wave: W7 ---