60732577f5
* Use Colored UI if stdout is a tty * Add format options to operator unseal * Add format test on operator unseal * Add -no-color output flag, and use BasicUi if no-color flag is provided * Move seal status formatting logic to OutputSealStatus * Apply no-color to warnings from DeprecatedCommands as well * Add OutputWithFormat to support arbitrary data, add format option to auth list * Add ability to output arbitrary list data on TableFormatter * Clear up switch logic on format * Add format option for list-related commands * Add format option to rest of commands that returns a client API response * Remove initOutputYAML and initOutputJSON, and use OutputWithFormat instead * Remove outputAsYAML and outputAsJSON, and use OutputWithFormat instead * Remove -no-color flag, use env var exclusively to toggle colored output * Fix compile * Remove -no-color flag in main.go * Add missing FlagSetOutputFormat * Fix generate-root/decode test * Migrate init functions to main.go * Add no-color flag back as hidden * Handle non-supported data types for TableFormatter.OutputList * Pull formatting much further up to remove the need to use c.flagFormat (#3950) * Pull formatting much further up to remove the need to use c.flagFormat Also remove OutputWithFormat as the logic can cause issues. * Use const for env var * Minor updates * Remove unnecessary check * Fix SSH output and some tests * Fix tests * Make race detector not run on generate root since it kills Travis these days * Update docs * Update docs * Address review feedback * Handle --format as well as -format
43 lines
1.3 KiB
Markdown
43 lines
1.3 KiB
Markdown
---
|
|
layout: "docs"
|
|
page_title: "operator rotate - Command"
|
|
sidebar_current: "docs-commands-operator-rotate"
|
|
description: |-
|
|
The "operator rotate" rotates the underlying encryption key which is used to
|
|
secure data written to the storage backend. This installs a new key in the key
|
|
ring. This new key is used to encrypted new data, while older keys in the ring
|
|
are used to decrypt older data.
|
|
---
|
|
|
|
# operator rotate
|
|
|
|
The `operator rotate` rotates the underlying encryption key which is used to
|
|
secure data written to the storage backend. This installs a new key in the key
|
|
ring. This new key is used to encrypted new data, while older keys in the ring
|
|
are used to decrypt older data.
|
|
|
|
This is an online operation and does not cause downtime. This command is run
|
|
per-cluster (not per-server), since Vault servers in HA mode share the same
|
|
storage backend.
|
|
|
|
## Examples
|
|
|
|
Rotate Vault's encryption key:
|
|
|
|
```text
|
|
$ vault operator rotate
|
|
Key Term 3
|
|
Install Time 01 May 17 10:30 UTC
|
|
```
|
|
|
|
## Usage
|
|
|
|
The following flags are available in addition to the [standard set of
|
|
flags](/docs/commands/index.html) included on all commands.
|
|
|
|
### Output Options
|
|
|
|
- `-format` `(string: "table")` - Print the output in the given format. Valid
|
|
formats are "table", "json", or "yaml". This can also be specified via the
|
|
`VAULT_FORMAT` environment variable.
|