Key rotation
This runbook helps you rotate Deedbox’s master key.
- On your schedule, or at once when the master key may have leaked.
-
Make a new key:
v2:$(openssl rand -base64 32). -
Put the new key first in the key ring, and keep the old one:
v2:<new>,v1:<old>. On Kubernetes, update the Secret thatkeys.masterKeySecretnames and restart the server. Deedbox wraps new keys with the first key and still reads the old ones. -
Re-wrap every tenant key and pseudonym secret with the new key. Events are not touched:
Terminal window deedbox keys rewrap --provider postgres --connection "$CASEBOX_DB" --from env:OLD_MASTER_KEY --to env:DEEDBOX_MASTER_KEY -
When
rewraphas finished, remove the old key from the ring and restart the server.
A local trial started with casebox up keeps its key in the database (database mode). Rotate by moving to environment or Azure Key Vault mode with the same steps.