Auto-Deploy on Push / verify-and-notify (push) Canceled after 0s
Issue #38 discussion surfaced a real bug: the TURN shared secret was duplicated - correctly SOPS-encrypted in coturn-secret.yaml, but also hardcoded in plaintext in synapse-values.yaml (a plain, non-SOPS ConfigMap), visible in git history. Also found turn_user_lifetime is 86400000ms (24h), not "short-lived" as previously assumed - raising the stakes of the leak somewhat. Extracted the turn config block into its own dedicated SOPS-encrypted Secret (synapse-turn-secret.yaml), wired via a second HelmRelease valuesFrom entry (same pattern already used for ess-mas-values-secret). Rotated the value while doing this, so the leaked plaintext secret is no longer live anywhere. Added checksum/rotated-at annotations (matrix-stack HelmRelease's existing element-config-checksum patch gets a sibling turn-secret-checksum; coturn's Deployment pod template gets a rotated-at annotation) so future rotations actually restart both consumers - Kubernetes doesn't restart running pods when a referenced Secret's content changes on its own. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>