Manage package signatures

Manage package signatures in Linux — with the four heights of help laid out: do it now, make it easier for the next person to accept, work out the right move when you are stuck, and learn the pattern so it stops coming back.

4prompt heights
Open it in the interactive atlas →

The four heights

The same task, four distances: today's deadline, the next reviewer, the stuck moment, the pattern.

Execute — do the immediate task

+
Send the updated package signing key rotation checklist to Priya in procurement and to Marco the…
Send the updated package signing key rotation checklist to Priya in procurement and to Marco the release manager for e-signature, signers in that order, with a Friday deadline so package builds stay signed next week. Before routing it, confirm the checklist includes key generation steps on the signing host keymaster01, the pubkey distribution path to apt-repo01, and the emergency rollback procedure.

Improve — make it easier to accept

+
Before I send the package signature policy to the client's engineering leads, make it easy to…
Before I send the package signature policy to the client's engineering leads, make it easy to approve. Put the expiry and rotation cadence up top, make the verification command examples prominent, and flag any steps that require offline key use or hardware token support that would slow adoption.

Decide — diagnose the stuck moment

+
I rotated the repository signing key on keymaster01 and then the nightly builds failed verification…

I rotated the signing key and packages now fail verification

I rotated the repository signing key on keymaster01 and then the nightly builds failed verification on apt-repo01. I'm the package maintainer, the release lead is Marco, and the deployment window is this evening. I'm worried that if I roll back the key we break recently deployed artifacts and if I leave it broken we miss the release. I don't know whether the new key was uploaded to all mirrors or whether clients still trust the old key. What's the most likely mismatch and the safest next step right now?

Become — change the pattern

+
Over the past year we have several incidents where key rotations were delayed or done incompletely,…

We repeatedly miss key rotations and cause build failures

Over the past year we have several incidents where key rotations were delayed or done incompletely, causing automated builds to fail. I'm the security lead, Marco handles releases, and we use a single signing host. I suspect our one-person bottleneck and lack of verification checks are the root causes. What operational habit should we change first to stop these incidents, and how should I measure that it's working?

Next to this one

Other operating system work people do in Linux.

Every task here came from the work, not from a feature list — which is why the prompts name what you want done and never the button that does it. The tool changes; the work does not.
Copyright © LLOS.ai · 2026 — original pedagogy, voice, and design — all rights reserved.

The rest of the map

Same library, five ways in.