localca: Rotation support part 1 - #971
Open
Taahir Ahmed (ahmedtd) wants to merge 1 commit into
Open
Conversation
Taahir Ahmed (ahmedtd)
requested review from
Eitan Yarmush (EItanya),
haiyanmeng and
Max Thompson (thompsonmax)
August 15, 2026 03:53
This commit fleshes out localca's rotation support by changing the interface so that signing operations should always go through a pool. All existing in-tree callers are converted over to this pattern. This ensures that signing can properly continue as a CA pool is rotated, without requiring any process restarts. The pool is periodically reloaded from disk in the course of signing operations, with the loaded data being cached for up to a minute. Some code for storing the CA state using PEM files was removed because it seemed to be dead. Follow-on changes will give localjwt a similar treatment, and add administrative commands for running rotations on pools.
Taahir Ahmed (ahmedtd)
force-pushed
the
ca-rotation
branch
from
August 15, 2026 04:24
cba5644 to
eba8eb4
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This commit fleshes out localca's rotation support by changing the interface so that signing operations should always go through a pool. All existing in-tree callers are converted over to this pattern. This ensures that signing can properly continue as a CA pool is rotated, without requiring any process restarts.
The pool is periodically reloaded from disk in the course of signing operations, with the loaded data being cached for up to a minute.
Some code for storing the CA state using PEM files was removed because it seemed to be dead.
Follow-on changes will give localjwt a similar treatment, and add administrative commands for running rotations on pools.