AAC Docs

aac tenant rotate-admin-key

AAC CLI 0.2.8MarkdownDocs 6b7d8268ba78

Replace this tenant's admin key with a new PUBLIC key.

Synopsis

aac tenant rotate-admin-key
  [-h]
  [--profile PROFILE]
  [--admin-url ADMIN_URL]
  [--data-plane-url DATA_PLANE_URL]
  [--output {json,table}]
  --tenant-admin-pubkey-file TENANT_ADMIN_PUBKEY_FILE
  [--tenant-id TENANT_ID]
  [--bootstrap-token BOOTSTRAP_TOKEN]

Arguments

Argument Type Required Default Description
-h, --help flag no — show this help message and exit
--profile value no — Profile to run under (selection: --profile > AAC_PROFILE > reserved baseline main). aac profile list shows what exists.
--admin-url value no — Admin-surface base URL (overrides profile).
--data-plane-url value no — Data-plane-surface base URL (overrides profile).
--output json | table no json Output mode: json (the default) or table.
--tenant-admin-pubkey-file value yes — Path to the PEM-encoded Ed25519 PUBLIC key that becomes the new ACTIVE tenant-admin key.
--tenant-id value no — Tenant to rotate (defaults to the profile/AAC_TENANT_ID identity).
--bootstrap-token value no — Ceremony bootstrap token (onboarding windows) — lets the ceremony operator rotate on the tenant's behalf while no session exists. Falls back to $AAC_BOOTSTRAP_TOKEN; without one the cached session rides.

Output

--output json (the default) prints one JSON document to standard output; --output table prints a readable table instead. Progress notes and diagnostics go to standard error, so the JSON stays parseable.

Exit codes

Code Meaning
0 Success.
1 The control plane or the identity provider rejected the request.
2 Usage error: an invalid flag, value or flag combination.
3 A local configuration or state problem: profile, credential file, cached session or agent.
4 Transport failure: an endpoint could not be reached.

Notes

Accepts and transmits the PUBLIC half only. It never generates or writes private-key material, and if you hand it a private key by mistake it refuses without transmitting or logging it — but it does READ the file you name, because refusing requires inspecting it. Replacement is IMMEDIATE and forward-only: the previous key stops verifying ingest JWSs at once (no grace window) and can never be reinstated. A trust anchor publisher holding the old private key must be given the new one and RESTARTED — it loads its key once at startup. Generate a keypair with: openssl genpkey -algorithm ed25519 -out tenant-admin.pem && openssl pkey -in tenant-admin.pem -pubout -out tenant-admin.public.pem