KSK rollover should only happen if previous rollover was completed
I found an issue that knot try to rollover KSK even when previous KSK rollover was not completed (DS was not submitted to upstream).
If previous KSK rollover was not confirmed there shouldn't be new one.
On this system there was submission check configured but because responsible persons never actually updated DS record on toplevel, knot tried to do another KSK rollover. Result was two CDS and CDNSKEY records, one for previous ksk and another for next one. I think best way to avoid this would be to only start timer for next KSK rollover after DS submission has been confirmed either by submission check or manually.