Offline, read-only planning for device credential-expiry cohorts. It never generates, exports, reads, or rotates production credentials.
This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.
Run the checked-in example
node bin/device-identity-rotation-planner.mjs --root examples/pass --policy policy.json --inventory inventory.json
node bin/device-identity-rotation-planner.mjs --root examples/fail --policy policy.json --inventory inventory.json
npm run checkRead the result
The CLI emits one JSON report: exit 0=pass (every due device assigned), 1=fail (known unsafe devices deferred), 2=incomplete (missing/unsupported evidence) or invalid configuration. Invalid options, root, or policy leave stdout empty. Unreadable or malformed inventory emits an incomplete report. Both file paths are realpath-confined beneath --root, strict UTF-8 and duplicate decoded JSON keys are enforced, and no files are written.
Where this check stops
Policy ≤65,536 bytes; inventory ≤1,048,576 bytes; ≤1,000 devices, ≤100 windows, ≤100 readiness checks, JSON depth ≤16, evaluation ≤5,000 ms with an injectable monotonic clock. expiryHorizonDays is 1–365, heartbeat age is 1,000–2,592,000,000 ms, and window capacity is 1–1,000. Boundary N is accepted, N+1 rejected. This tool does not contact devices, verify live reachability, create credentials, execute rotation, or perform rollback.
Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.
Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.