maqpna keys rotate
Rotate a signing or encryption key without downtime
Synopsis#
maqpna keys rotate identity [-n NS] [--grace 1h] [--jwks-wait 5m30s | --restart-gateway] [--no-finish | --finish [--force]]
maqpna keys rotate audit-checkpoint [-n NS] [--secret NAME]
maqpna keys rotate vault [-n NS] [--secret NAME] [--drop-old]
maqpna keys rotate attest [-n NS] --secret NAME [--grace 24h] [--no-finish | --finish [--force]]Description#
From the help of maqpna keys:
Common flags: --dry-run (print the plan only), --timeout (per rollout, default 5m), --gateway URL (used to confirm the result through the admin API when reachable). Deployments default to the chart names (maqpna-identity, maqpna-gateway, maqpna-attest, maqpna-operator); override with --deployment / --operator-deployment. See docs/runbooks/key-rotation.md.
Subcommands#
maqpna keys rotate identityRotate the identity broker's session-token signing key
maqpna keys rotate audit-checkpointRotate the audit ledger's checkpoint signing key
maqpna keys rotate vaultRotate the encryption key of the token vault (connected accounts)
maqpna keys rotate attestRotate the attestation service's response signing key
Examples#
maqpna keys rotate identity -n maqpna-system
maqpna keys rotate identity -n maqpna-system --finish
maqpna keys rotate audit-checkpoint -n maqpna-systemExit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |
Related commands#
Terminal demo#
This command needs a Kubernetes cluster with MAQPNA installed, so the recording shows its help. Try it against a cluster from Install.