Skip to content

docs: update signing key rotation guidance#1401

Open
charIeszhao wants to merge 2 commits intomasterfrom
charles-update-signing-key-rotation-docs
Open

docs: update signing key rotation guidance#1401
charIeszhao wants to merge 2 commits intomasterfrom
charles-update-signing-key-rotation-docs

Conversation

@charIeszhao
Copy link
Copy Markdown
Member

@charIeszhao charIeszhao commented Apr 28, 2026

Summary

Update the English signing key rotation docs to match the new staged OIDC private key rotation behavior. This adds the Next / Current / Previous status model, documents the Cloud 4-hour grace period, explains OSS grace period configuration via PRIVATE_KEY_ROTATION_GRACE_PERIOD and CLI --gracePeriod, and adds the new environment variable to the core configuration reference.

Testing

Tested locally

Checklist

  • .changeset
  • unit tests
  • integration tests
  • necessary TSDoc comments

Copilot AI review requested due to automatic review settings April 28, 2026 14:57
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates Logto signing key rotation documentation to reflect staged OIDC private key rotation (Next/Current/Previous), including grace-period behavior for Cloud and configuration options for OSS.

Changes:

  • Document staged OIDC private key rotation with Next/Current/Previous statuses and lifecycle.
  • Add OSS grace-period configuration via PRIVATE_KEY_ROTATION_GRACE_PERIOD and CLI --gracePeriod.
  • Add PRIVATE_KEY_ROTATION_GRACE_PERIOD to the core service configuration reference.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 5 comments.

File Description
docs/logto-oss/using-cli/rotate-signing-keys.mdx Updates OSS CLI rotation guidance to include staged rotation/grace period and key retention model.
docs/developers/signing-keys.mdx Updates Console UI rotation behavior/status model and documents Cloud/OSS grace period behavior.
docs/concepts/core-service/configuration.md Adds PRIVATE_KEY_ROTATION_GRACE_PERIOD to environment variable reference.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread docs/developers/signing-keys.mdx Outdated
Comment thread docs/developers/signing-keys.mdx Outdated
Comment thread docs/logto-oss/using-cli/rotate-signing-keys.mdx Outdated
Comment thread docs/logto-oss/using-cli/rotate-signing-keys.mdx Outdated
Comment thread docs/logto-oss/using-cli/rotate-signing-keys.mdx Outdated
@cloudflare-workers-and-pages
Copy link
Copy Markdown

cloudflare-workers-and-pages Bot commented Apr 28, 2026

Deploying logto-docs with  Cloudflare Pages  Cloudflare Pages

Latest commit: 3fdae9b
Status: ✅  Deploy successful!
Preview URL: https://6a4eabcf.logto-docs.pages.dev
Branch Preview URL: https://charles-update-signing-key-r.logto-docs.pages.dev

View logs

@cloudflare-workers-and-pages
Copy link
Copy Markdown

cloudflare-workers-and-pages Bot commented Apr 28, 2026

Deploying logto-docs-tutorials with  Cloudflare Pages  Cloudflare Pages

Latest commit: 3fdae9b
Status: ✅  Deploy successful!
Preview URL: https://9e295ebb.logto-docs-tutorials.pages.dev
Branch Preview URL: https://charles-update-signing-key-r.logto-docs-tutorials.pages.dev

View logs

@charIeszhao charIeszhao requested a review from a team April 29, 2026 04:26
Copy link
Copy Markdown
Contributor

@wangsijie wangsijie left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 PR Review

Updates the English signing-key rotation docs to describe staged OIDC private key rotation for Cloud and OSS, including grace-period configuration and key lifecycle states.

  • 🔒 Security: clean
  • 🏗️ Architecture: 0 high, 1 medium
  • 👨‍💻 Engineering: 0 high, 2 medium

Verdict: ⚠️ Needs attention

Comment thread docs/developers/signing-keys.mdx
Comment thread docs/logto-oss/using-cli/rotate-signing-keys.mdx
Comment thread docs/logto-oss/using-cli/rotate-signing-keys.mdx
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants