MAQPNADocs

maqpna keys rotate attest

Rotate the attestation service's response signing key

Operate

Synopsis#

maqpna keys rotate attest [-n NS] --secret NAME [--grace 24h] [--no-finish | --finish [--force]]

Flags#

FlagTypeDescriptionDefault
--deploymentstringDeployment reading the key (default: the chart's)none
--drop-oldswitchvault: remove the old key once no account is sealed under itnone
--dry-runswitchprint what would changenone
--finishswitchfinish a swapped rotation (remove the old key)none
--forceswitchwith --finish: do not wait for the grace period to endnone
--gatewaystringgateway base URL (env MAQPNA_GATEWAY_URL; default: the context's gateway)none
--gracedurationidentity: how long old tokens stay valid (>= the longest token TTL, default 1h); attest: dual-key window before the attest service signs with the new key (>= the longest session renewal window, default 24h)none
--jwks-waitdurationidentity: wait for the gateways to refresh the broker JWKS (gateway identity.jwksRefreshSeconds + margin)5m30s
--no-finishswitchstop after the swap; finish later with --finishnone
--oidc-token-filestringfile holding an OIDC access token for the admin API (env MAQPNA_OIDC_TOKEN_FILE); wins over --tokennone
--operator-deploymentstringattest: operator Deployment injecting the response public keymaqpna-operator
--restart-gatewayswitchidentity: restart the gateway (loads the JWKS at start) instead of waiting --jwks-waitnone
--secretstringSecret holding the key (default: found from the Deployment's volume)none
--timeoutdurationtimeout of each rollout5m0s
--tokenstringstatic admin token (env MAQPNA_ADMIN_TOKEN; dev/break-glass)none

The global flags (--context, -o, --no-color, ...) work with every command.

What happens when you run it#

  • Talks to the gateway: --gateway, else MAQPNA_GATEWAY_URL, else the current context's gateway (maqpna context).
  • Authenticates to the admin API with the token stored by maqpna login, --oidc-token-file, or a static --token (MAQPNA_ADMIN_TOKEN).
  • --dry-run: print what would change.
  • --force: with --finish: do not wait for the grace period to end.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)

Terminal demo#

maqpna keys rotate attest --help.cast

This command needs a Kubernetes cluster with MAQPNA installed, so the recording shows its help. Try it against a cluster from Install.