what is the best practices work flow on pgp pubkeys handling when adding repos?