The scheduled run for one realm: gives it its first key, or rotates it if it is due and this node still owns the run.
the trust realm id
Optionalctx: any
the scheduler's run context, with nowMs() and stillOwner()
a promise of the run's result: the kvno, whether it rotated, and when the next is due
Forwards to
KrbtgtRotation.rotateDue()on the installed instance.