Service Mesh Platform  ·  View 17 of 31  ·  5 · Runtime

Root Rotation

Replacing the mesh root without a single handshake failing, by making every step additive and measuring before taking the next.

Editable source SVG draw.io All views
T − 30 d · add Overlap T0 · switch T0 → 24 h T + 30 d · retire Trust bundle Old + new root Reaches every proxy Old root removed Intermediates Re-signed by new root SPIRE CAs chain to new Workload SVIDs New issuance, new chain Old-chain SVIDs expire Gate Bundle coverage 100% Skewed handshakes = 0 Hold if any proxy lags Old-chain count → 0 Removal PR, two keys Root Rotation — Additive, With a 30-Day Overlap Every step can be reversed until the last, and the last is taken only after the overlap has been measured, not assumed. v 1.0 · owner Security Architecture · date 2026-09

Decisions

  • The new root is distributed 30 days before anything chains to it. The switch waits until the drift exporter shows 100% of proxies holding both roots.
  • Handshake failures are classified by cause. A failure caused by an unknown root is reported as trust-bundle skew and never as an authorisation denial, so nobody debugs the wrong policy.
  • Removing the old root is the only irreversible step. It needs a change in the identity repository approved by two keyholders.

Why rehearse it

  • A ten-year root is rotated by people who have never done it, from a runbook nobody has run. The Phase 3 rehearsal rotates a staging mesh's root every year so the ceremony is a habit, not an archaeology exercise.

Assumptions

  • Root lifetime 10 years, 30-day overlap. Intermediates are re-signed during the overlap; they do not have to wait for their own yearly rotation.