01 / USAGE
How the intended workflow fits together
- 01
Sweeps every credential source weekly and keeps a full inventory — the report shows what's healthy, not just what's dying.
- 02
Inside 30 days: it opens the rotation PR from your runbook template and assigns the owner from resource tags.
- 03
Zero-noise design: one PR per credential, deduplicated across weeks, escalating to a human ping only at 7 days.
02 / CONFIGURATION
Read the configuration contract
Each credential type maps to a rotation runbook. Unknown types get an inventory alert, not a PR.
Illustrative configuration. Adapt only after verifying the implementation, schema and service permissions.
# sweep.yaml
schedule: '0 9 * * 1' # Mon IST
sources: [acm, kms, gcp-sa, vault]
extra_paths:
- k8s://cert-manager/certificates
threshold: 30d
rotate:
acm: runbooks/rotate-acm.md
gcp-sa: runbooks/rotate-sa.md
notify: owner_from_tags # falls back to #platform03 / EVIDENCE
What an output could look like
This authored example describes the intended result format. It is not evidence that a live run occurred.
$ expiry-sweep report
swept 214 credentials across 4 sources
● 209 healthy (> 30d)
⚠ 4 rotation PRs open (oldest: 12d)
🚨 1 at 6 days → escalated to @rahul
lapses in last 18 months: 0 ✓04 / IMPLEMENTATION REFERENCE
Review the setup sketch
The original command sketch is preserved for design context. It is not a verified installation recipe. Confirm that the package or repository exists and review its implementation before running anything.
Show illustrative setup commands
brew install supraj/tap/expiry-sweep
expiry-sweep init --aws --gcp --vault https://vault.acme.dev