{"id":"service-account-issuer-24h-grace","text":"Changing `spec.serviceAccountIssuer` on the Authentication resource does not immediately invalidate existing tokens — a 24-hour grace period allows internal components to transition.","truth_value":"IN","source":"entries/2026/03/05/en-documentation-openshift_container_platform-417-html-config_apis-authenticatio.md","source_url":"","source_hash":"ac2f2829344c99cf","justifications":[],"dependents":[],"metadata":{},"explanation":{"steps":[{"node":"service-account-issuer-24h-grace","truth_value":"IN","reason":"premise"}]}}