Skip to main content

Module secrets

Module secrets 

Source
Expand description

A stack’s secrets: references into its org’s store, by name and version.

A deployed stack never holds a value. Each top-level secret its services use becomes a SecretBinding: the name in the org’s store (or a driver’s reference), the driver, and the version deployed. Values are read from the store when they are delivered, and a new version is a new revision, so the services using it roll.

  • external: true names an existing secret in the org.
  • file: and environment: are read by the deploying client, and age: is decrypted with the daemon’s key; all three are stored as local secrets named <stack>_<key>, as swarm does, and removed with the stack.
  • driver: X, name: REF is read through driver X.

Structs§

RefreshSchedule
When each driver-backed binding is next due for a version check.
SecretBinding
One top-level secret a stack uses, as deployed.

Functions§

bind
Bind every secret file’s services use, for deploying it as stack in org. given holds the values of file:/environment: secrets, read by the client. Values the stack owns are stored now, and only when changed, so an unchanged value keeps its version. With dry_run nothing is written; the versions are what a deploy would produce.
owned_name
<stack>_<key>: where a stack keeps a secret it was given a value for.
resolve
The values of a file’s store-backed secrets (external, age, driver), for isb up, which runs no stack. file: and environment: secrets are skipped: the client reads those itself.
used_keys
The top-level secrets a file’s services use (as files or variables).
values
The values of the given keys, read from the store through the stack’s bindings.

Type Aliases§

Refreshed
A forced refresh: the (driver, version) of every binding to the name, and the stacks that rolled.