Four facts must stay separate.
Settings carry a name, not the provider key.
Describe is value-free and writes are one-way.
The managed rc.8 document is owner-only plaintext.
Same-UID tools may still read user-owned files.
Choose a boundary that matches the threat.
Useful only when ciphertext and key authority separate.
Verify access policy and whether tools can invoke it.
Use a dedicated account, VM, or container with a limited short-lived key.
If a bearer key may have been read, stop the runtime and revoke it at the provider before migrating storage.
Primary evidence.
Protect the whole resolution path.
The complete guide includes a threat matrix, current rc.8 controls, adjacent-key limitations, keychain requirements, operating patterns, safe migration, incident response, and fifteen acceptance gates.
Read the complete guide