connect/ca: Add a method for manually forcing a root rotation
Open
theme/certificates
theme/reliability
type/enhancement
- Dominant language
- Go
- Stars
- 30.1k
- Forks
- 4.6k
- Avg merge
- 1d 18h
- Merged PRs (30d)
- 39
Description
Currently there's no way to force the CA to rotate the active root outside of changing the CA config in a particular way to cause a rotation. We should add an api/CLI command explicitly for forcing this, to make a more clear workflow for this.
Contributor guide
Research direction
Start by locating the connect/ca implementation and its existing root-rotation path, then inspect the API and CLI entry points. Define the explicit force-rotation workflow and verify that both interfaces trigger the intended CA root rotation without requiring a configuration change.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- api, cli, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100