RotateServiceAccountSecretResultDto
Namespace: Meshmakers.Octo.Communication.Contracts.DataTransferObjects
Answer of POST {tenantId}/v1/adapter/{adapterRtId}/serviceAccount/rotateSecret
(AB#5032, client surface AB#5048) β the mirror of the communication controller's
RotateServiceAccountSecretResultDto.
public record RotateServiceAccountSecretResultDto : IEquatable<RotateServiceAccountSecretResultDto>
Inheritance Object β RotateServiceAccountSecretResultDto
Implements IEquatable<RotateServiceAccountSecretResultDto>
Remarks:
π΄ It deliberately carries no secret, and adding one here would defeat the decision
taken server-side: the plaintext lives in exactly two places β the tenant's
ServiceAccountConfiguration entity and the identity client's hash β and a third copy
travelling back through the SDK would end up in proxy logs, shell history and CI output.
Everything a caller needs in order to act is in RotateServiceAccountSecretResultDto.RequiresPipelineRedeploy and
RotateServiceAccountSecretResultDto.Message.
Propertiesβ
ClientIdβ
The identity client whose secret was replaced.
public string ClientId { get; set; }
Property Valueβ
ConfigurationWellKnownNameβ
RtWellKnownName of the configuration entity holding the new secret β the key the mesh
adapter resolves its execution identity by.
public string ConfigurationWellKnownName { get; set; }
Property Valueβ
WasCreatedβ
true when the adapter had no service account yet and the call provisioned one instead
of rotating. Nothing was invalidated in that case.
public bool WasCreated { get; set; }
Property Valueβ
RequiresPipelineRedeployβ
true when the adapter's pipelines / data flows must be redeployed before the new
secret takes effect β the adapter caches the credentials in the pipeline's
GlobalConfiguration at registration time and never refreshes them. A caller that
drops this flag produces the "rotation done, still broken" situation.
public bool RequiresPipelineRedeploy { get; set; }
Property Valueβ
Messageβ
Operator-facing summary, including the redeploy instruction when one is needed.
public string Message { get; set; }
Property Valueβ
Constructorsβ
RotateServiceAccountSecretResultDto(String, String, Boolean, Boolean, String)β
Answer of POST {tenantId}/v1/adapter/{adapterRtId}/serviceAccount/rotateSecret
(AB#5032, client surface AB#5048) β the mirror of the communication controller's
RotateServiceAccountSecretResultDto.
public RotateServiceAccountSecretResultDto(string ClientId, string ConfigurationWellKnownName, bool WasCreated, bool RequiresPipelineRedeploy, string Message)
Parametersβ
ClientId String
The identity client whose secret was replaced.
ConfigurationWellKnownName String
RtWellKnownName of the configuration entity holding the new secret β the key the mesh
adapter resolves its execution identity by.
WasCreated Boolean
true when the adapter had no service account yet and the call provisioned one instead
of rotating. Nothing was invalidated in that case.
RequiresPipelineRedeploy Boolean
true when the adapter's pipelines / data flows must be redeployed before the new
secret takes effect β the adapter caches the credentials in the pipeline's
GlobalConfiguration at registration time and never refreshes them. A caller that
drops this flag produces the "rotation done, still broken" situation.
Message String
Operator-facing summary, including the redeploy instruction when one is needed.
Remarks:
π΄ It deliberately carries no secret, and adding one here would defeat the decision
taken server-side: the plaintext lives in exactly two places β the tenant's
ServiceAccountConfiguration entity and the identity client's hash β and a third copy
travelling back through the SDK would end up in proxy logs, shell history and CI output.
Everything a caller needs in order to act is in RotateServiceAccountSecretResultDto.RequiresPipelineRedeploy and
RotateServiceAccountSecretResultDto.Message.