To reduce blast radius and enable safer operational rollover if a key leaks.
Signing keys should be treated like real production infrastructure. Rotation limits long-term exposure and gives operators a controlled path to replace secrets without freezing the auth system.