What break-glass is
It's a small file — your escrow file — that holds your backup key locked behind a passphrase you memorise. On its own the file is useless; with your passphrase it hands the key back. That means the file is safe to keep anywhere, and the only thing you truly have to protect is a phrase in your head.
1 Create your escrow file Administrator sets up You pick the passphrase
Your Larauna administrator runs one command on the machine that holds your key. It asks for a passphrase twice — you type it (the administrator doesn't need to see it). Choose a long, memorable phrase.
That produces one small file, larauna-key-escrow.json. Nothing secret is shown on screen; the passphrase is never stored.
2 Keep the escrow file Your copy
Because the file is locked by your passphrase, it's safe to keep almost anywhere — pick a place you won't lose:
- Your cloud storage (Google Drive, iCloud, Dropbox) — even a shared drive is fine.
- Email it to yourself, or keep it in your notes.
- Print it and file it. (It's just text — it can be re-typed.)
3 Memorise your passphrase The one thing to protect
This is the whole point — and the one thing you must not lose. A good passphrase is long but memorable: a short sentence you'll always recall, e.g. "my first car was a blue corolla 1998". Longer beats complicated.
Do
- Use a long phrase only you would know.
- Keep it in your head — or, at most, in your password manager as a separate entry.
- Optionally, share it with one deeply trusted person as a fallback.
Don't
- Write the passphrase on or next to the escrow file — that defeats it entirely.
- Use something guessable (a birthday, "password123").
- Assume you'll remember a random one — make it memorable.
4 Test it once, now
Prove your passphrase works while it's fresh. This checks the passphrase without revealing the key:
If you ever need it — recovering
On the bad day — both everyday copies gone — this brings your key back. Find your escrow file, then:
That's your key back. From there, a restore is the normal process — your Larauna administrator can take it from here.