Commands / kosa8 key rotate
kosa8 key rotate
Rewrap every snapshot key under a new KEK and destroy the old one
Creates a new KEK, rewraps every snapshot's data key under it, and then overwrites and deletes the old KEK. Snapshots here keep opening. Every copy of a key record wrapped under the old KEK — in a pushed snapshot, an exported bundle, a backup — stops opening anywhere: this is the crypto-shred that reaches copies kosa8 cannot delete. Machines that share the old KEK must import the new one to keep exchanging snapshots. Audited.