maqpna keys
Rotate signing and encryption keys without downtime
Synopsis#
maqpna keys rotate identity [-n NS] [--grace 1h] [--jwks-wait 5m30s | --restart-gateway] [--no-finish | --finish [--force]]
maqpna keys rotate audit-checkpoint [-n NS] [--secret NAME]
maqpna keys rotate vault [-n NS] [--secret NAME] [--drop-old]
maqpna keys rotate attest [-n NS] --secret NAME [--grace 24h] [--no-finish | --finish [--force]]Description#
Common flags: --dry-run (print the plan only), --timeout (per rollout, default 5m), --gateway URL (used to confirm the result through the admin API when reachable). Deployments default to the chart names (maqpna-identity, maqpna-gateway, maqpna-attest, maqpna-operator); override with --deployment / --operator-deployment. See docs/runbooks/key-rotation.md.
Subcommands#
Examples#
maqpna keys rotate identity -n maqpna-system
maqpna keys rotate identity -n maqpna-system --finish
maqpna keys rotate audit-checkpoint -n maqpna-systemExit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |
Related commands#
Terminal demo#
This command needs a Kubernetes cluster with MAQPNA installed, so the recording shows its help. Try it against a cluster from Install.