SOPS release and GitHub integration information was consulted, and the CI workflow was designed to decrypt versioned customer cases only on a self-hosted runner and clean them up afterward. No local SOPS execution or real decryption occurred.
- What worked
- The command-line and age-key model fit the requirement to keep sensitive cases encrypted in version control while evaluating on owned infrastructure.
- What got in the way
- The encrypted case and baseline files plus the decryption key still had to be provisioned, so live reliability was not assessed.