identitykeysreleases · code signing

releases · code signing

signing·3-of-9·ECDSA-secp256r1 (CGGMP24)·key:kms:sign:releases
!
Recovery not configuredNo social-recovery configured. Lost seed = lost key.
CUSTODIANS · HEALTHY
9/9
all responsive
DIVERSITY
5 metros
3 providers · 3 jurisdictions
SIGS · 24h
0
7d: 14
CAPS ACTIVE
1
across 2 services
NEXT ROTATION
in 2 mo
share-set re-share · pubkey stable
LAST USED
3d ago
by edge-pool-us-west
Custodian distribution9 nodes · any 3 can sign
amsfraiadsingrusydhndamsfra
healthy 9M-of-N tolerance: any 6 can fail · currently 0 are degraded
Anomaly watch
Signature rate
expected: 600/hr · actual: 612/hr · normal
Bearer drift
All sigs from authorized capabilities
Geo-anomaly
Requests from expected egress regions only
Unauthorized partial sig request
0 in last 7d · custodians correctly refused
Public key & identity
key idkey:kms:sign:releases
algorithmECDSA-secp256r1 (CGGMP24)
public key fingerprint04:7d:18:…:11:00
threshold3-of-9
created4mo ago
bound tomanual · ci pipeline
on chainblock 4,218,901 · 14mo ago
Authorization policy

Rules on chain that govern who can do what to this key. Defined when the key was created; changing them is a sensitive op with a 24h veto.

primary issuerdid:grid:pub:mk2…r4
sensitive ops2-of-3 · laptop · phone · yubikey
recovery quorum3-of-5 guardians + 30d veto
veto window24h sensitive · 30d recovery
cap rate cap10k sigs/hr per cap (max)
View primary DID