-- The control plane's own signing identity. -- -- novox/hq ADR 0004: a node takes instruction from the control plane behind the broker, and each -- declaration is verified by its signature, every time. The public half of this key travels in -- every enrolment token; the private half never leaves this context. -- -- Why not pin only the broker: that would make the control plane's authority transitive. A -- compromised broker could then forge declarations, and since the host applies whatever the link -- delivers, that is the whole machine. The transport is verified once at connect; the instruction -- is verified on arrival. create table signing_key ( id uuid primary key default gen_random_uuid(), -- Ed25519. Fixed rather than a column: a key that carries its own algorithm invites a caller -- to be told which one to use, and the two sizes below are Ed25519's. public bytea not null check (octet_length(public) = 32), private bytea not null check (octet_length(private) = 64), created timestamptz not null default now(), -- Retiring a signing key is a fleet-wide operation with an overlapping rollover -- every node -- holds the public half, delivered in a token it may have received months ago. So keys are -- retired, never deleted, and more than one may be valid at a time during a rollover. retired timestamptz ); -- The rollover is what makes this a partial index rather than a plain unique constraint: exactly -- one key may be signing at any moment, while any number of retired ones remain verifiable. create unique index signing_key_one_active on signing_key ((retired is null)) where retired is null;