Skip to content
CI/CD
Skill

/crypto-key-rotation

AES 密钥轮换设计与开发指南,涵盖 AES_KEY_SHA 指纹、CryptoHelper、CryptoKeyRefreshWriter、历史密钥 used-*-keys、aes.refresh 启动刷新任务。当用户新增加密表字段、接入密钥轮换、修改 Token/凭证/证书加解密、配置 aes.refresh 或 used-git-keys 时使用。

BOOST
From plugin
bk-ci
2.5k43 skills
Install
$ npx -y skills add tencentblueking/bk-ci --skill crypto-key-rotation --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/crypto-key-rotation

Context preview

The summary Claude sees to decide when to auto-load this skill.

AES 密钥轮换设计与开发指南,涵盖 AES_KEY_SHA 指纹、CryptoHelper、CryptoKeyRefreshWriter、历史密钥 used-*-keys、aes.refresh 启动刷新任务。当用户新增加密表字段、接入密钥轮换、修改 Token/凭证/证书加解密、配置 aes.refresh 或 used-git-keys 时使用。

SKILL.md

crypto-key-rotation.SKILL.md
name: crypto-key-rotation
description: AES 密钥轮换设计与开发指南,涵盖 AES_KEY_SHA 指纹、CryptoHelper、CryptoKeyRefreshWriter、历史密钥 used-*-keys、aes.refresh 启动刷新任务。当用户新增加密表字段、接入密钥轮换、修改 Token/凭证/证书加解密、配置 aes.refresh 或 used-git-keys 时使用。
related_skills:
  - database-design
  - common-technical-practices
  - repository-module-architecture
token_estimate: 800

AES 密钥轮换

完整设计与开发指南见 [docs/dev/crypto_key_rotation.md](../../../docs/dev/crypto_key_rotation.md)。

修改加密表、`AES_KEY_SHA`、`CryptoKeyRefreshWriter` 或 `aes.refresh` 前,必须先阅读该文档,再按其中的四条链路(DDL / DAO / Helper / Writer)实现。新服务还必须加 `CryptoKeyRefreshStartup`(见文档 5.5)。

Ships withbk-ci

蓝鲸持续集成平台(蓝盾)

Get the whole plugin

Other skills on bk-ci.

00-bkci-global-architecture
Skill

00-bkci-global-archite…

用于跨模块开发、排查链路归属、判断某个需求应该落在哪个 BK-CI 模块,或需要快速理解流水线全链路协作时使用。单模块修改时优先读取对应模块 skill,而不是停留在这里。

agent-module-architecture
Skill

agent-module-architect…

处理 BK-CI Agent 构建机侧能力时使用,例如守护进程、心跳、Ask 轮询、任务拉起、升级更新和与 Dispatch/Worker 的协作。当用户要改构建机宿主侧行为而不是…

api-interface-design
Skill

api-interface-design

设计 BK-CI API 契约时使用,例如 Resource 路径设计、HTTP 方法选择、请求响应对象、错误码和版本策略。当用户要定义接口而不是实现业务逻辑时优先使用。

auth-module-architecture
Skill

auth-module-architectu…

处理 BK-CI Auth 模块时使用,例如 RBAC 权限校验、用户组与资源管理、IAM 集成、授权迁移和 OAuth2 认证。当用户要改权限平台实现而不是单次权限模型变更时优先使用。