An artifact signature is useful only when a verifier accepts the right signer, issuer, trust root, and artifact digest. Rotating a signing key or identity-provider certificate can strand valid releases if admission trusts only the old material; trusting both indefinitely leaves an obsolete authority active. The verification policy, signing job, and deployment admission path must move in a coordinated window.
Signature trust rollover: rotate verification roots without disabling admission
Operational decision
A payment service moves its build signer to a new identity. First inventory every verifier in CI, admission, and disaster recovery, including offline environments. Add the new trusted identity or root while retaining the old one for a bounded overlap, then sign a disposable image digest with the new path and verify it through each gate. The text contract keeps the transition reviewable. Reject a signature from an unrelated identity and reject a valid signature over a different digest. Promote one new-signed canary, check its running digest, then retire the old signer and remove old trust after all required rollback artifacts have either been re-signed under an approved path or have an explicit exception with expiry. If a signing service is unavailable during a rollout, pause promotion; do not turn verification off globally. Record which verifier accepted each release and how its trust material was distributed.
Payment signer rollover
Phase 1: inventory CI, admission, and recovery verifiers
Phase 2: trust old and new identities for a bounded window
Phase 3: verify new-signed canary digest; reject wrong signer and digest
Phase 4: move rollback inventory or issue narrow exception
Phase 5: remove old trust and test old-signer denialCost and verification
Running two trusted paths temporarily increases the number of credentials that can authorize a release. Removing the old path too soon can make rollback impossible. Each verifier update costs deployment and test time, especially in disconnected clusters. Monitor signature failures by reason rather than only a pass rate. Trust-root updates must be distributed through an authenticated channel; a fetched root from the same untrusted artifact being verified is circular trust.
Common Mistakes
- Do not disable admission verification when one signer becomes unavailable.
- Do not keep the old signer trusted forever after the migration.
- Do not accept a correct signer attached to the wrong digest.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Software supply chain: SBOM and provenance at admission
- Kubernetes admission policy: reject an unsafe workload before scheduling
- Immutable artifacts and release provenance
- Policy exceptions: make a temporary bypass expire and prove its scope
