AAC Docs

aac agent renew

AAC CLI 0.2.8MarkdownDocs 6b7d8268ba78

Replace the short-lived certificates; archive the old material.

In "The CLI creates a development CA" mode, reissues the workload, receipt and HTTPS certificates with new keys; the development CA is reissued only when expired or within one day of expiry, or with --ca, and a new CA needs the publisher to publish the new anchor. In "I bring my own CA" mode nothing is reissued: pass the replacement certificates your issuer produced, each with its key file, and --ca-cert-file if your CA certificate changed too.

Synopsis

aac agent renew
  [-h]
  --agent AGENT
  [--output {json,table}]
  [--profile PROFILE]
  [--ca]
  [--workload-cert-file PATH]
  [--terminal-cert-file PATH]
  [--tls-cert-file PATH]
  [--ca-cert-file PATH]
  [--workload-key-file PATH]
  [--terminal-key-file PATH]
  [--tls-key-file PATH]

Arguments

Argument Type Required Default Description
-h, --help flag no — show this help message and exit
--agent value yes — Target agent name under ~/.aac/agents/.
--output json | table no json Output mode (JSON by default).
--profile value no — Optional check that the agent belongs to this profile; the agent itself records its profile, so the flag is never required.
--ca flag no — Also reissue the development CA now.

I bring my own CA

Your own issuer has signed the agent's certificates, and your CA private key never reaches this machine. Certificate source alone does not qualify a production deployment. Pass only what your issuer re-signed: each replacement certificate with its key file, or on its own when the key is unchanged. Add --ca-cert-file only when your CA certificate changed too, and then replace every certificate it did not sign. Your CA's key must be Ed25519 or EC P-256, and it must have signed each certificate with Ed25519 or ECDSA-with-SHA-256. The two identity keys may be Ed25519 or EC P-256; the HTTPS key must be EC P-256. RSA is not supported: the sidecar cannot verify against it.

Argument Type Required Default Description
--workload-cert-file value no — Use this certificate your issuer signed for the agent's identity.
--terminal-cert-file value no — Use this certificate your issuer signed for the agent's receipts.
--tls-cert-file value no — Use this certificate your issuer signed for the agent's HTTPS listener.
--ca-cert-file value no — Use this existing certificate authority certificate.
--workload-key-file value no — Use this existing private key for the agent's identity.
--terminal-key-file value no — Use this existing private key for the agent's receipts.
--tls-key-file value no — Use this existing private key for the agent's HTTPS listener.

Output

--output json (the default) prints one JSON document to standard output; --output table prints a readable table instead. Progress notes and diagnostics go to standard error, so the JSON stays parseable.

Exit codes

Code Meaning
0 Success.
1 The control plane or the identity provider rejected the request.
2 Usage error: an invalid flag, value or flag combination.
3 A local configuration or state problem: profile, credential file, cached session or agent.
4 Transport failure: an endpoint could not be reached.