Add internal wallet key rotation runbook - #573
Draft
Jossec101 wants to merge 1 commit into
Draft
Conversation
Operations runbook for rotating the NodeGuard internal wallet master seed as proactive hygiene: preflight SQL inventories (incl. the hardened-path STOP gate and the channel close-address long tail), the seed ceremony via the remote signer's seed-ceremony CLI, Lambda env configuration with the snapshot->merge->apply pattern, the InternalWallets INSERT that flips the current wallet, a hot single-sig canary that proves the new seed end to end, wallet recreation + liquidity-rule/funds-destination re-pointing, UI-driven drains, archiving, and the long-tail policy (keep MF_<old> forever, mark it Compromised once old single-sig wallets are empty). Known gaps are documented as caveats (stale add-key modal on old wallets, mixed-fingerprint Lambda throw, silent FKs, global subderivation counter, hardened-path limitation) rather than fixed, per scope decision.
Jossec101
marked this pull request as draft
August 19, 2026 10:59
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Operations runbook for rotating the NodeGuard internal wallet master seed
as proactive hygiene: preflight SQL inventories (incl. the hardened-path
STOP gate and the channel close-address long tail), the seed ceremony via
the remote signer's seed-ceremony CLI, Lambda env configuration with the
snapshot->merge->apply pattern, the InternalWallets INSERT that flips the
current wallet, a hot single-sig canary that proves the new seed end to
end, wallet recreation + liquidity-rule/funds-destination re-pointing,
UI-driven drains, archiving, and the long-tail policy (keep MF_
forever, mark it Compromised once old single-sig wallets are empty).
Known gaps are documented as caveats (stale add-key modal on old wallets,
mixed-fingerprint Lambda throw, silent FKs, global subderivation counter,
hardened-path limitation) rather than fixed, per scope decision.
Stack created with GitHub Stacks CLI • Give Feedback 💬