Read-only ActivityPub → atproto bridge for the threadiverse using Coves lexicons

feat(config,identity): read under two KEKs, write under one master

BRIDGE_KEK_PREVIOUS (optional, no dev default, refused if byte-equal to BRIDGE_KEK) names the key being rotated away from. The custodian seals only under the current KEK and falls back to the previous one exactly when the current fails AEAD authentication — malformed blobs keep their ValidationError untouched, so a data incident is never misread as a wrong-KEK incident, and a both-keys failure reads byte-identically to the single-KEK failure operators already alert on. This is deployable alone: with PREVIOUS unset, behavior is unchanged. The rotate-kek re-seal walk is the follow-up run. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>


+83 -18
3 changed files