Skip to main content
Version: v25.1.0

Key Rotation Overview

This document is the entry point for all AI Factory key rotation procedures. It describes which key types exist, their rotation schedule, and which rotations require downtime. The runbooks for those procedures are linked below.

For the full key management policy (lifecycle, approval workflow, audit trail), see Key Management Policy.

Key Inventory

Key TypeScopeRotation PeriodDowntime?
SSH keys (mido_infra)Infrastructure access (all hosts, both environments)Every 6 months (aligned with release cycle)No
TLS certificatesHAProxy, RabbitMQ, Octavia CA, backend services1 yearBrief (service restart)
WireGuard VPN keysOperator VPN peer keys1 yearBrief (VPN reconnect)
Ansible Vault passwordsSecrets encryption at rest (per environment)1 yearNo

Key Rotation Runbooks