Expand description
A stack’s secrets: references into its org’s store, by name and version.
A deployed stack never holds a value. Each top-level secret its services
use becomes a SecretBinding: the name in the org’s store (or a
driver’s reference), the driver, and the version deployed. Values are read
from the store when they are delivered, and a new version is a new
revision, so the services using it roll.
external: truenames an existing secret in the org.file:andenvironment:are read by the deploying client, andage:is decrypted with the daemon’s key; all three are stored aslocalsecrets named<stack>_<key>, as swarm does, and removed with the stack.driver: X, name: REFis read through driver X.
Structs§
- Refresh
Schedule - When each driver-backed binding is next due for a version check.
- Secret
Binding - One top-level secret a stack uses, as deployed.
Functions§
- bind
- Bind every secret
file’s services use, for deploying it asstackinorg.givenholds the values offile:/environment:secrets, read by the client. Values the stack owns are stored now, and only when changed, so an unchanged value keeps its version. Withdry_runnothing is written; the versions are what a deploy would produce. - owned_
name <stack>_<key>: where a stack keeps a secret it was given a value for.- resolve
- The values of a file’s store-backed secrets (
external,age,driver), forisb up, which runs no stack.file:andenvironment:secrets are skipped: the client reads those itself. - used_
keys - The top-level secrets a file’s services use (as files or variables).
- values
- The values of the given keys, read from the store through the stack’s bindings.
Type Aliases§
- Refreshed
- A forced refresh: the (driver, version) of every binding to the name, and the stacks that rolled.