noCV
VAULT-106 · Rotate with controlled overlap

Accept old and new webhook signatures only during a bounded overlap

Practice briefTaskAdvanced

The supplier rotates signing keys gradually across senders. Switching instantly drops valid traffic; retaining every old key forever defeats retirement.

Focused work estimate
3h 30m + prerequisites
Priority in the scenario
High
Engineering practice
Key rotation · Validity windows · Input trust boundaries

Estimated field mix

  • Security70%
  • Integrations30%

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Your next step

Review it, then add it to your workspace.

The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.

Project context

A fictional supplier integration signs incoming webhooks and uses an outbound API credential. Operators currently replace environment values by hand. Build with a deterministic secret-store adapter and fabricated keys only; no live provider account or production credential is part of the exercise.

Setup prerequisites

  • Cryptographic hash APIs
  • HTTP webhook handling
  • Access control

Preceding work

Complete these dependencies, or supply their agreed outputs before taking this ticket.

Acceptance criteria

  • Accept only the configured active and retiring versions during their explicit validity windows.
  • Reject retired or revoked versions regardless of timestamp tolerance.
  • Record the non-secret verifying version identity for accepted webhook receipts.

Implementation constraints

  • Bound the candidate key set; an untrusted key ID cannot trigger arbitrary provider lookups.

Verification to include

  • Accept both fixture versions inside overlap and only the new version after retirement.
  • Try a revoked version and an unknown attacker-controlled key ID; assert rejection without broad lookup.

Deliverables

  • Signing overlap policy and boundary-time tests

Rollout and recovery

Stage the new version, begin bounded overlap, then retire the old version after fixture sender convergence.

Value of the work

For the engineer: Practice credential lifecycle design, overlap windows, authenticated webhooks, and failure recovery without handling real secrets.

For the team: Review whether an engineer can make rotation auditable and fail closed while preserving availability and replay safety.

Evidence boundaries

Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.