Incident Response Runbooks¶
These runbooks are for managed sovereign operation. They are intentionally plain: stop the bad trust path, preserve evidence, restore service, and document what changed.
Operator Key Compromise¶
Use this when an operator signing key may have been exposed.
Revoke the key on the running service — no restart required:
genesis-mesh admin revoke-operator-key <compromised-key-id> \ --na https://na.example.org \ --operator-key keys/other-operator.key \ --operator-key-id <another-privileged-key-id> \ --reason key_compromise
The key stops authenticating on the very next request. Rejection happens before its signature is checked and before its nonce is consumed, so it cannot act at all — including revoking other operators.
This requires a privileged-tier key, and the service refuses to revoke the last usable operator key (
409 last_active_operator_key). Configure a second operator key before an incident so this path is available.Confirm old-key admin requests now fail with
401 Unknown admin key. The audit log records the true reason (admin_auth_failedwithreason: revoked_key) plus anoperator_key_revokedevent naming who performed the revocation.Rotate to a new operator key and record the new key ID. Adding a key still requires updating
OPERATOR_PUBLIC_KEYS_JSON(andOPERATOR_KEY_TIERS_JSON) and restarting — only removal is live.Revocation is terminal: a revoked key ID cannot be restored on the running service. Bringing it back means editing configuration and restarting, deliberately.
Export audit events around the compromise window:
genesis-mesh managed audit-export \ --db-path /var/lib/genesis-mesh/na.db \ --output ./incident-audit.jsonl
Review admin actions signed by the compromised key.
Revoke or supersede any trust material created by the compromised key.
Bad Treaty Issued¶
Use this when a recognition treaty was issued with the wrong subject sovereign, public key, role, validity window, or metadata.
Revoke the treaty:
curl -X POST https://<na>/admin/recognition-treaties/<treaty-id>/revoke
Confirm
/connectome.jsonshows the revoked edge.Export audit events for the treaty:
genesis-mesh managed audit-export \ --db-path /var/lib/genesis-mesh/na.db \ --output ./bad-treaty-audit.jsonl \ --event-type recognition_treaty_issued
Issue a corrected treaty only after the subject public keys and scope are independently checked.
Notify affected operators if any attestation was accepted under the bad treaty.
Bad Revocation Feed Imported¶
Use this when a signed feed was imported from the wrong issuer, stale sequence, wrong public key, or wrong incident scope.
Stop importing new feeds from the affected issuer until the source is understood.
Export
sovereign_revocation_feed_importedandsovereign_revocation_feed_rejectedaudit events.Review
/connectome.jsonrevocation blast radius.Restore from the most recent known-good DB backup if the imported feed must be removed from state.
Re-import the corrected feed.
Confirm the expected attestations are accepted or rejected after import.
Database Restore¶
Use this when DB state is corrupt, accidental trust data was deleted, or a bad import must be rolled back.
Stop the Network Authority.
Create a pre-restore copy of the current DB.
Restore the selected backup:
genesis-mesh managed restore \ --db-path /var/lib/genesis-mesh/na.db \ --backup /backups/genesis-mesh-na-known-good.db \ --pre-restore-backup /backups/na-before-restore.db \ --yes
Start the Network Authority.
Check:
curl -fsS http://127.0.0.1:8443/healthz curl -fsS http://127.0.0.1:8443/readyz curl -fsS http://127.0.0.1:8443/connectome.json
Export audit events after restore and attach them to the incident record.
Revocation Blast-Radius Review¶
Use this after any membership attestation or treaty revocation that may affect another sovereign.
Fetch
/connectome.json.Review
revocation_blast_radius.Identify accepting sovereigns affected by the revoked trust material.
Confirm each affected sovereign has imported the latest feed.
Record expected accept/reject behavior for the affected attestations.