← Files AkinatorARCHIVED FILE
evals/fixtures/brownfield/ops/playbooks/rotate-the-signing-key.md
631 Bytes · Oct 4, 2026 · 12:31 UTC
# Rotate the signing key ## When Quarterly, or immediately on suspected compromise. ## Steps 1. Generate the new key: `python scripts/gen_key.py > keys/next.pem` 2. Publish it alongside the current key so both verify: `docker compose restart api` 3. Wait for the longest token lifetime - 24 hours - before removing the old key. Removing it early invalidates every live session. 4. Promote and remove: `mv keys/next.pem keys/current.pem && docker compose restart api` ## Rollback Before step 4, restore `keys/current.pem` from the backup and restart. After step 4 the old key is gone; issued tokens cannot be recovered.
SHA-256: a7a34a173ae03d38505c8a1989c1f02d5c117c0647abf9e54f943ee5ea460afd