Expand description
A stack’s secrets: references into its org’s store, by name and version.
A deployed stack never holds a value. Each top-level secret its services
use becomes a SecretBinding: the name in the org’s store (or a
driver’s reference), the driver, and the version deployed. Values are read
from the store when they are delivered, and a new version is a new
revision, so the services using it roll.
external: truenames an existing secret in the org.file:andenvironment:are read by the deploying client, andage:is decrypted with the daemon’s key; all three are stored aslocalsecrets named<stack>_<key>, as swarm does, and removed with the stack.driver: X, name: REFis read through driver X.
Structs§
- Applied
- Where a secret’s
rotatecommand made a new value take effect. - Bound
- What
bind_reportingbound, and which values it reused. - Cycle
- What a new version of a secret did to one service of a stack.
- Refresh
Schedule - When each driver-backed binding is next due for a version check.
- Reused
- A
file:/environment:secret deployed with the value an earlier deploy of the stack stored, because this deploy gave it none. - Secret
Binding - One top-level secret a stack uses, as deployed.
- Stale
Secret - A secret a replica runs an older version of (
on_change: none, or a restart still to come).
Constants§
- LABEL_
SECRETS - Instance config key (without
user.) holding the versions of therestart/nonesecrets its app last started with, as a JSON object. A replica whose versions are behind the stack’s is stale.
Functions§
- bind
- Bind every secret
file’s services use, for deploying it asstackinorg.givenholds the values offile:/environment:secrets, read by the client; one it lacks reuses the value an earlier deploy stored. Values the stack owns are stored now, and only when changed, so an unchanged value keeps its version. Withdry_runnothing is written; the versions are what a deploy would produce. - bind_
reporting bind, naming the secrets that reused a stored value. Withoutreuse, afile:/environment:secretgivenlacks is an error.- cycled_
stacks - The stacks with a service that cycles (rolls or restarts), by name.
- env_
exposure_ warning - One warning for the secrets an OCI image takes as variables: those are
instance config (
environment.KEY), plain text to anyone who can read the instance (incus config show). A system image’s stay in a 0600 file. - owned_
name <stack>_<key>: where a stack keeps a secret it was given a value for.- parse_
versions_ label LABEL_SECRETSread back;Nonewhen absent or unreadable.- poll_
versions - The current version of every
(org, driver, name), one polling round: each driver is asked once per org for all its names, so it can answer names that share a version (fields of one 1Password item) with one lookup. - resolve
- The values of a file’s store-backed secrets (
external,age,driver), forisb up, which runs no stack.file:andenvironment:secrets are skipped: the client reads those itself. - stale
- Which of
want’s secrets a replica that started withhaveruns an older version of. A secret missing fromhaveis not stale: the replica predates the setting, and is taken to run what is bound. - used_
keys - The top-level secrets a file’s services use (as files or variables).
- values
- The values of the given keys, read from the store through the stack’s bindings.
- versions_
label LABEL_SECRETS’s value.