Skip to main content

Module secrets

Module secrets 

Source
Expand description

A stack’s secrets: references into its org’s store, by name and version.

A deployed stack never holds a value. Each top-level secret its services use becomes a SecretBinding: the name in the org’s store (or a driver’s reference), the driver, and the version deployed. Values are read from the store when they are delivered, and a new version is a new revision, so the services using it roll.

  • external: true names an existing secret in the org.
  • file: and environment: are read by the deploying client, and age: is decrypted with the daemon’s key; all three are stored as local secrets named <stack>_<key>, as swarm does, and removed with the stack.
  • driver: X, name: REF is read through driver X.

Structs§

Applied
Where a secret’s rotate command made a new value take effect.
Bound
What bind_reporting bound, and which values it reused.
Cycle
What a new version of a secret did to one service of a stack.
RefreshSchedule
When each driver-backed binding is next due for a version check.
Reused
A file:/environment: secret deployed with the value an earlier deploy of the stack stored, because this deploy gave it none.
SecretBinding
One top-level secret a stack uses, as deployed.
StaleSecret
A secret a replica runs an older version of (on_change: none, or a restart still to come).

Constants§

LABEL_SECRETS
Instance config key (without user.) holding the versions of the restart/none secrets its app last started with, as a JSON object. A replica whose versions are behind the stack’s is stale.

Functions§

bind
Bind every secret file’s services use, for deploying it as stack in org. given holds the values of file:/environment: secrets, read by the client; one it lacks reuses the value an earlier deploy stored. Values the stack owns are stored now, and only when changed, so an unchanged value keeps its version. With dry_run nothing is written; the versions are what a deploy would produce.
bind_reporting
bind, naming the secrets that reused a stored value. Without reuse, a file:/environment: secret given lacks is an error.
cycled_stacks
The stacks with a service that cycles (rolls or restarts), by name.
env_exposure_warning
One warning for the secrets an OCI image takes as variables: those are instance config (environment.KEY), plain text to anyone who can read the instance (incus config show). A system image’s stay in a 0600 file.
owned_name
<stack>_<key>: where a stack keeps a secret it was given a value for.
parse_versions_label
LABEL_SECRETS read back; None when absent or unreadable.
poll_versions
The current version of every (org, driver, name), one polling round: each driver is asked once per org for all its names, so it can answer names that share a version (fields of one 1Password item) with one lookup.
resolve
The values of a file’s store-backed secrets (external, age, driver), for isb up, which runs no stack. file: and environment: secrets are skipped: the client reads those itself.
stale
Which of want’s secrets a replica that started with have runs an older version of. A secret missing from have is not stale: the replica predates the setting, and is taken to run what is bound.
used_keys
The top-level secrets a file’s services use (as files or variables).
values
The values of the given keys, read from the store through the stack’s bindings.
versions_label
LABEL_SECRETS’s value.

Type Aliases§

Polled
One polling round’s answers: the version of each (org, driver, name), or why it could not be read.
Refreshed
A forced refresh: the (driver, version) of every binding to the name, and what the new version did, per service.