Optional expiry for SSH and deploy keys.
- Migration 0061:
ssh_keys.expires_at.keys add --ttlandrepo deploy-key add --ttl(same parsing astoken create --ttl; zero and negative refused). - An expired key is refused at authentication (without touching the auth limiter), on every exec, and in system mode;
LiveSSHKeysleaves it out, so the sweep cuts connections open when it expires. - An expiring key's session carries its expiry, so it is refused the credential-minting commands, like an expiring token.
keys listandrepo deploy-key listshow last use and expiry;--jsongains the fields.repo deploy-key addnow rejects an unknown flag instead of taking it as the repository.token listat a terminal shows a future expiry as a time, not "just now" (#286).- Users, Parity, API and Architecture pages; #277 leaves Known-Gaps; CHANGELOG.
Stacked on !483 (token-delegation).