Skip to main content

Rotation

The Rotation screen (page heading Zero-downtime rotation) shows each certificate set's two slots and lets you promote a staged replacement into service only after the Mesh Node proves it is healthy.

ConsoleRotation

What it's for​

Most managed identities are certificate sets with two slots:

  • ACTIVE: the certificate currently serving traffic.
  • STANDBY: a replacement that has been issued and deployed (staged) but is not yet serving.

Promotion swaps them. The old certificate keeps serving until the standby passes its health check, so a failed rotation never causes an outage.

What you see​

Rotation screen with a certificate set card showing ACTIVE and STANDBY slots, the exact health URL field and the Verify and promote button
A certificate set ready to promote.

Each certificate set is a card:

PartContent
GENERATION nHow many times the set has been issued.
TitleThe endpoint identity.
SubtitleProfile ID and rotation mode (dual slot or in place).
Overlap windowHow long the old and new certificates overlap, in minutes. While a promotion is in progress this reads Node command · pending verification.
ACTIVE / STANDBY slotsEach slot shows its health, serial number, expiry, state and Deployed … ago or Not deployed. An unused slot shows Empty slot.
Exact health URLOnly shown when a standby exists.
Verify & promoteStarts the promotion. Reads Awaiting Mesh Node while a promotion is in progress.

Slot health is healthy, unhealthy or unknown. Slot state is staged, serving, draining, retired or revoked.

At the bottom, the Rotation safety invariant card reminds you: A failed stage or health check never removes the active certificate. Promotion and rollback are idempotent across node restarts.

If no certificate has been issued yet, the screen shows No certificate sets yet: Dual-slot state appears after the first managed identity is issued.

Promote a standby certificate​

  1. Find the certificate set. Check that the STANDBY slot shows a certificate in state staged.
  2. Check the Exact health URL. The console pre-fills it from the first non-wildcard name on the staged certificate, as https://<name>/health. Change it if your service exposes health elsewhere.
  3. Select Verify & promote.
  4. Wait for the Mesh Node to report back. The button reads Awaiting Mesh Node until it does. Select Refresh in the top bar to update the card.

The console confirms: Promotion command queued. The assigned Mesh Node will verify the exact certificate and report completion.

The Mesh Node verifies a 2xx response from the health URL while serving this exact staged certificate before switching traffic. After promotion, the previous certificate moves to the standby slot as draining.

Health URL rules​

  • It must start with https://. Verify & promote stays disabled otherwise.
  • It must return a 2xx response while the staged certificate is being served.
  • It is fixed while a promotion is in progress.

Where rotation settings come from​

The renewal timing, overlap, health grace period, rollback window and whether promotion is manual or automatic come from the workload profile in your policy. Configure them in Policies under Workload and application profiles:

SettingValues
PromotionOperator verifies & promotes, or Automatic after exact health (only for profiles that allow NGINX, Apache, Java keystore or HashiCorp Vault deployment)
Renew before (hours)When to start renewing before expiry
Overlap (minutes)0–10,080
Health grace (seconds)10–3,600
Rollback window (minutes)1–1,440

To promote many certificate sets in coordinated waves, use Migrations. See also Zero-downtime rotation.

Permissions​

ActionRoles
View certificate setsEvery role
Verify & promoteApplication Owner, PKI Operator, Tenant Admin. Requires MFA within the last ten minutes.

Troubleshooting​

SymptomCause and fix
Verify & promote is greyed outThere is no standby, a promotion is already pending, or the health URL does not start with https://.
The card stays on Awaiting Mesh NodeThe node has not reported completion. Check the node on Mesh nodes and the deployment integration on Integrations.
Promotion did not happen and the old certificate is still activeThe health check failed, so the node kept the active certificate. Fix the service or the health URL, then promote again.
The promotion is rejected with an MFA messageYour MFA is older than ten minutes. Sign in again.