Skip to content

Add admin endpoint to rotate shared bootstrap API keys

Placeholder ppxd requested to merge feat/bootstrap-key-rotation-endpoint into main

Summary

Phase 4 of the bootstrap-key redesign. Re-filed after PR #337 was auto-closed when its base (PR #339, Phase 3) merged.

Endpoint `POST /system/bootstrap-keys/rotate` lets System Administrators invalidate the shared bootstrap key (Tentacle or KubernetesAgent surface) on suspicion of leak. Body: `{ "surface": "Tentacle" | "KubernetesAgent" }` (case-insensitive). Response: `{ description, disabledCount }`.

Already-registered agents are unaffected -- they use machine identity + server thumbprint, not the bootstrap key. Rotation only invalidates future install-script generations.

`IAccountService.DisableApiKeysByDescriptionAsync` disables every active key matching the canonical description and invalidates the API-key cache.

Test plan

  • Unit: 5241/5241 pass (5 new handler tests covering surface mapping, case-insensitivity, first-ever-rotation, unknown surface error)
  • Integration: `BootstrapKeyRotation_EndToEnd_FindAfterDisable_ReturnsNull` walks the full mint → disable → find=null DB path via IRepository (bypasses IUserTokenService DI requirement)
  • CI on predecessor PR (#337) was fully green (9/9) before re-target

🤖 Generated with Claude Code

Merge request reports

Loading