rotateDeks: (
options: any,
) =>
| { ok: boolean; rotated: any[]; why: string }
| { ok: boolean; rotated: any[]; why?: undefined } = rotateDeks
Type Declaration
-
- (
options: any,
):
| { ok: boolean; rotated: any[]; why: string }
| { ok: boolean; rotated: any[]; why?: undefined }
-
Returns
| { ok: boolean; rotated: any[]; why: string }
| { ok: boolean; rotated: any[]; why?: undefined }
{ ok, rotated: [{ id, scope, realm, cls, activateAt }] }, or
{ ok: false, why } where DEKs are not stored
Rotates data encryption keys: a new DEK for every current slot this process can wrap for, matching the realm and class given (all when omitted), active after
keys.dataKeyActivationLeadSeconds. A slot that already has a DEK waiting to activate is left alone.