keys: optional expiry for SSH and deploy keys !486

merged merged by cmc on 2026-09-28 21:49 UTC · krz/gitbay:key-expiry into main

Discussion

cmc

Optional expiry for SSH and deploy keys.

  • Migration 0061: ssh_keys.expires_at. keys add --ttl and repo deploy-key add --ttl (same parsing as token create --ttl; zero and negative refused).
  • An expired key is refused at authentication (without touching the auth limiter), on every exec, and in system mode; LiveSSHKeys leaves it out, so the sweep cuts connections open when it expires.
  • An expiring key's session carries its expiry, so it is refused the credential-minting commands, like an expiring token.
  • keys list and repo deploy-key list show last use and expiry; --json gains the fields.
  • repo deploy-key add now rejects an unknown flag instead of taking it as the repository.
  • token list at a terminal shows a future expiry as a time, not "just now" (#286).
  • Users, Parity, API and Architecture pages; #277 leaves Known-Gaps; CHANGELOG.

Stacked on !483 (token-delegation).

Closes #277 Closes #286