MAQPNADocs

maqpna keys

Rotate signing and encryption keys without downtime

Operate

Synopsis#

maqpna keys rotate identity         [-n NS] [--grace 1h] [--jwks-wait 5m30s | --restart-gateway] [--no-finish | --finish [--force]]
maqpna keys rotate audit-checkpoint [-n NS] [--secret NAME]
maqpna keys rotate vault            [-n NS] [--secret NAME] [--drop-old]
maqpna keys rotate attest           [-n NS] --secret NAME [--grace 24h] [--no-finish | --finish [--force]]

Description#

Common flags: --dry-run (print the plan only), --timeout (per rollout, default 5m), --gateway URL (used to confirm the result through the admin API when reachable). Deployments default to the chart names (maqpna-identity, maqpna-gateway, maqpna-attest, maqpna-operator); override with --deployment / --operator-deployment. See docs/runbooks/key-rotation.md.

Subcommands#

Examples#

maqpna keys rotate identity -n maqpna-system
maqpna keys rotate identity -n maqpna-system --finish
maqpna keys rotate audit-checkpoint -n maqpna-system

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)

Terminal demo#

maqpna keys --help.cast

This command needs a Kubernetes cluster with MAQPNA installed, so the recording shows its help. Try it against a cluster from Install.