Skip to content

feat: handle RSA key alignment when migrating to shared XTM Composer #87

Description

Parent: #86

Context

Each XTM Composer instance has its own RSA private key (used for connector credentials encryption). The key is loaded as a singleton at startup (src/main.rs — private_key()). When migrating existing customers to a shared instance, the two former instances have different keys. Connectors encrypted with the old key won't decrypt with the new one.

Options

  1. Support multiple keys (quick workaround): Allow the shared composer to hold both private keys and try decryption with each. Enables seamless migration without re-encrypting credentials on the platform side.
  2. RSA key renewal/rotation (clean solution): Add the ability to rotate the RSA key on the platform side, so both platforms can be re-keyed to match the shared composer's key. Already tracked in feat: handle renewal of the RSA key #72.

Both options may be valuable — option 1 for migration, option 2 for ongoing operational needs.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    featureType: new feature or capability (feat:).

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions