Skip to content

[Spec 030] Router credential key rotation #75

Description

@XnLemon

Scope

Track Spec 030, Router Credential Key Rotation, as the next Stage 2 operational-governance slice after the trusted invocation loop and PR #74.

Draft spec: specs/030-router-key-rotation/spec.md on branch codex/030-router-key-rotation.

Delivery gate

  • Merge PR [codex] add public Agent share URLs #74 before implementation work begins.
  • Resolve all three security-policy clarifications in the Spec before planning.
  • Preserve the existing Router-mediated invocation, exact Release provenance, per-request credential, streaming/cancellation, nested-call, and Invocation Ledger semantics.

Outcome

Operators can perform a planned signing-key rotation and an explicitly governed emergency response without unknown-key acceptance, implicit signer fallback, secret leakage, or rotation facts being written into the Invocation Ledger.

Child tasks

Child task links will be added after creation.

Non-goals

No automatic retry, alternate signer, remote key discovery, retired-key compatibility, cross-replica replay implementation, new secret manager, or enterprise RBAC/approval system.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:contractsVersioned schemas and API contractsstatus:blockedBlocked by another issue or pull requesttaskParent task tracking a multi-issue delivery

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions