Skip to content

Add admin endpoint to rotate shared bootstrap API keys

Summary

Phase 4 of the bootstrap-key redesign. Depends on PR #336 (Phase 3).

New endpoint `POST /system/bootstrap-keys/rotate` lets System Administrators invalidate the shared bootstrap key (Tentacle or KubernetesAgent surface) on suspicion of leak. Body: `{ "surface": "Tentacle" | "KubernetesAgent" }` (case-insensitive). Response: `{ description, disabledCount }`.

Already-registered agents are unaffected -- they use machine identity + server thumbprint, not the bootstrap key. Rotation only invalidates future install-script generations.

`IAccountService.DisableApiKeysByDescriptionAsync` disables every active key matching the canonical description and invalidates the API-key cache.

Test plan

  • Unit: 5241/5241 pass (5 new handler tests covering surface mapping, case-insensitivity, first-ever-rotation, unknown surface error)
  • Integration: `BootstrapKeyRotation_EndToEnd_GenerateScriptAfterRotation_GetsFreshKey` walks the full mint → rotate → find=null DB path
  • Build: zero errors

🤖 Generated with Claude Code

Merge request reports

Loading