Skip to content

P1-key-ops: signer key lifecycle drills (rotation, revocation, incident runbooks) #320

@omarespejel

Description

@omarespejel

Summary

Operationalize key management beyond implementation code: rotation, revocation, and incident drills.

Problem

Even with signer isolation, production risk remains high without repeatable lifecycle operations.

Scope

  • Define key lifecycle policy for owner/session/signer keys:
    • rotation cadence
    • revocation triggers
    • emergency disable path
  • Add drill scripts and checklist for:
    1. normal rotation
    2. compromised signer credential incident
    3. forced session mass-revocation
  • Ensure logs are tamper-evident and correlated to drill IDs.
  • Document minimal required controls for DFNS/HSM-backed profiles.

Acceptance Criteria

  • Rotation drill runnable on Sepolia and documented
  • Incident drill produces auditable artifacts and tx references
  • Runbooks include rollback and recovery steps
  • Maintainer checklist added for pre-release readiness

Related

Metadata

Metadata

Assignees

Labels

area:infraCI/spec/conformance and toolingarea:securitySecurity hardening and threat-model correctnessenhancementNew feature or requestpriority:P1High leverage / next

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions