Every guide on secret rotation ends with "and then update the consumers." That sentence is where production dies.
I run two self-hosted n8n instances for an automation studio in Israel. This morning I counted what they hold: 114 credentials, referenced from 1,311 nodes across 260 workflows. The single most-used credential (a Postgres connection) sits in 233 nodes in 80 workflows, 40 of them active. The WhatsApp gateway key is in 106 nodes.
Between August 20 and August 25 I rotated four secrets. Three of them took something down. Each one failed in a different way, and none of the three failures was inside n8n. That is the part worth writing down.
Failure 1: the copy you forgot (2.5 days, zero alerts)
August 20. I rotated a Chatwoot API token. The token is used by a WAHA→Chatwoot bridge, and the bridge keeps its own copy of the token per inbox app. Six apps, six copies. I updated four.






