plc: always keep signing key in rotationKeys

Lewis: May this revision serve well! <lu5a@proton.me>
This commit is contained in:
Lewis
2026-06-26 18:52:12 +03:00
committed by Tangled
parent 39a2e40b35
commit 28f2e04019
14 changed files with 395 additions and 129 deletions
+13
View File
@@ -62,6 +62,12 @@ async fn main() -> ExitCode {
eprint!("{e}");
return ExitCode::FAILURE;
}
if let Some(key) = config.secrets.plc_rotation_key.as_deref()
&& let Err(reason) = tranquil_pds::plc::validate_rotation_did_key(key)
{
eprintln!("secrets.plc_rotation_key (PLC_ROTATION_KEY) {reason}");
return ExitCode::FAILURE;
}
if !*ignore_secrets
&& let Some((cert, key)) = config.server.tls.material()
&& let Err(e) = tls::load_certified_key(cert, key)
@@ -90,6 +96,13 @@ async fn main() -> ExitCode {
return ExitCode::FAILURE;
}
if let Some(key) = config.secrets.plc_rotation_key.as_deref()
&& let Err(reason) = tranquil_pds::plc::validate_rotation_did_key(key)
{
error!("secrets.plc_rotation_key (PLC_ROTATION_KEY) {reason}");
return ExitCode::FAILURE;
}
tranquil_config::init(config);
tranquil_pds::metrics::init_metrics();