maqpna keys rotate attest
Rotate the attestation service's response signing key
Synopsis#
maqpna keys rotate attest [-n NS] --secret NAME [--grace 24h] [--no-finish | --finish [--force]]Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--deployment | string | Deployment reading the key (default: the chart's) | none |
--drop-old | switch | vault: remove the old key once no account is sealed under it | none |
--dry-run | switch | print what would change | none |
--finish | switch | finish a swapped rotation (remove the old key) | none |
--force | switch | with --finish: do not wait for the grace period to end | none |
--gateway | string | gateway base URL (env MAQPNA_GATEWAY_URL; default: the context's gateway) | none |
--grace | duration | identity: how long old tokens stay valid (>= the longest token TTL, default 1h); attest: dual-key window before the attest service signs with the new key (>= the longest session renewal window, default 24h) | none |
--jwks-wait | duration | identity: wait for the gateways to refresh the broker JWKS (gateway identity.jwksRefreshSeconds + margin) | 5m30s |
--no-finish | switch | stop after the swap; finish later with --finish | none |
--oidc-token-file | string | file holding an OIDC access token for the admin API (env MAQPNA_OIDC_TOKEN_FILE); wins over --token | none |
--operator-deployment | string | attest: operator Deployment injecting the response public key | maqpna-operator |
--restart-gateway | switch | identity: restart the gateway (loads the JWKS at start) instead of waiting --jwks-wait | none |
--secret | string | Secret holding the key (default: found from the Deployment's volume) | none |
--timeout | duration | timeout of each rollout | 5m0s |
--token | string | static admin token (env MAQPNA_ADMIN_TOKEN; dev/break-glass) | none |
The global flags (--context, -o, --no-color, ...) work with every command.
What happens when you run it#
- Talks to the gateway:
--gateway, elseMAQPNA_GATEWAY_URL, else the current context's gateway (maqpna context). - Authenticates to the admin API with the token stored by
maqpna login,--oidc-token-file, or a static--token(MAQPNA_ADMIN_TOKEN). --dry-run: print what would change.--force: with--finish: do not wait for the grace period to end.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |
Related commands#
Terminal demo#
This command needs a Kubernetes cluster with MAQPNA installed, so the recording shows its help. Try it against a cluster from Install.