Skip to main content
← Back to list
01Issue
FeatureOpenSwamp CLIPublic
AssigneesNone

Relationships

#2540 serve: rotate the external token-secrets key

Opened by stack72 · 9/25/2026

Follow-up from swamp-club#2324, which added an opt-in external key for the _token-secrets control-plane vault (serve.yaml token-secrets block naming a vault and secret).

That change supports exactly one external key: the control plane records a marker with the key HMAC fingerprint, and every instance must present the same key. There is no way to rotate it. Replacing the secret in the vault makes serve refuse to start (fingerprint mismatch), and every token would need re-minting.

Proposal: support a versioned key set, for example the block accepting a previous key alongside the current one. On start, serve re-encrypts entries that open with the previous key under the current key (the same resumable, marker-last pass the migration uses), then records the new fingerprint. Blobs could carry a key id so a mixed fleet during rotation can still read both. Needs a story for HA: all instances must have both keys before any instance switches.

02Bog Flow
◉OPEN○TRIAGED○IN PROGRESS○SHIPPED

Open

9/25/2026, 5:21:30 PM

No activity in this phase yet.

03Sludge Pulse

Sign in to post a ripple.