Skip to main content
Version: v25.1.5

Key Rotation Overview

This document is the entry point for all AIsware key rotation procedures. It describes which key types exist, their rotation schedule, and which rotations require downtime. The runbooks for those procedures are linked below.

For the full key management policy (lifecycle, approval workflow, audit trail), see Key Management Policy.

Key Inventory

Key TypeScopeRotation PeriodDowntime?
SSH keys (mido_infra)Infrastructure access (all hosts, both environments)Every 6 months (aligned with release cycle)No
TLS certificatesHAProxy, RabbitMQ, Octavia CA, backend services1 yearBrief (service restart)
Ceph RGW TLS certificateS3-compatible object gateway (environments with ceph_rgw_tls_enabled: true)2 yearsNo (rolling daemon redeploy)
WireGuard VPN keysOperator VPN peer keys1 yearBrief (VPN reconnect)
Ansible Vault passwordsSecrets encryption at rest (per environment)1 yearNo

Key Rotation Runbooks