Skip to content

[Spec 030] Resolve signing-key rotation policy and ADR #76

Description

@XnLemon

Parent

#75 (#75)

Goal

Resolve the three policy decisions that currently block Spec 030 planning. Do not implement runtime behavior in this task.

Decisions required

  1. Distribution ownership: confirm the recommended operator-managed deployment configuration with explicit per-instance readiness, or approve an online platform key-discovery/distribution service.
  2. Routine lifecycle gates: confirm the recommended prepare -> all verifiers ready -> activate -> evidence of last old-key issuance -> drain for the greatest approved credential lifetime -> retire flow, with manual rollback only before retirement.
  3. Compromise response: confirm the recommended immediate old-key issuance stop and verification revocation, accepting explicit availability impact, or define a bounded containment window and risk owner.

Acceptance criteria

  • specs/030-router-key-rotation/spec.md contains no unresolved [NEEDS CLARIFICATION] markers.
  • An ADR records the selected distribution, activation, retirement, rollback, and compromise semantics.
  • The fallback inventory records zero new automatic fallback, alternate key lookup, retry, or retired-key compatibility behavior.
  • The selected policy names the owner, trigger, observable evidence, failure response, and recovery boundary for each decision.

Dependencies

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:contractsVersioned schemas and API contractsquestionFurther information is requestedstatus:blockedBlocked by another issue or pull request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions