Zum Hauptinhalt springen

SecretSweepReportDto

Namespace: Meshmakers.Octo.Communication.Contracts.DataTransferObjects

Report of the secret sweep of one tenant, as returned by bot-services (GET {tenantId}/v1/jobs/secret-sweep/report, GET system/v1/secrets/reports; AB#5539). Carries counts, CK type ids, runtime ids and attribute paths - never a value, never ciphertext.

public class SecretSweepReportDto

Inheritance Object → SecretSweepReportDto

Properties​

TenantId​

Tenant.

public string TenantId { get; set; }

Property Value​

String

Mode​

The requested mode. Writing modes are followed by a SecretSweepModeDto.Verify step that describes the state after the sweep.

public SecretSweepModeDto Mode { get; set; }

Property Value​

SecretSweepModeDto

Trigger​

What started the sweep.

public SecretSweepTriggerDto Trigger { get; set; }

Property Value​

SecretSweepTriggerDto

Outcome​

Outcome.

public SecretSweepOutcomeDto Outcome { get; set; }

Property Value​

SecretSweepOutcomeDto

Reason​

Why the sweep was skipped or failed, or a remark. Never contains a value.

public string Reason { get; set; }

Property Value​

String

StartedAt​

Start (UTC).

public DateTime StartedAt { get; set; }

Property Value​

DateTime

CompletedAt​

End (UTC).

public DateTime CompletedAt { get; set; }

Property Value​

DateTime

BackupFileName​

File name of the pre-sweep dump on the bot service, or null when none was taken.

public string BackupFileName { get; set; }

Property Value​

String

ActiveKeyId​

Active key id of the key ring at the time of the sweep, or null when no key is configured.

public string ActiveKeyId { get; set; }

Property Value​

String

StrictModeActive​

True when strict mode was in force for the environment.

public bool StrictModeActive { get; set; }

Property Value​

Boolean

StrictModeViolation​

True when strict mode was in force and the final state still holds legacy values (clear text or enc:v1).

public bool StrictModeViolation { get; set; }

Property Value​

Boolean

RemainingLegacyValues​

Clear-text plus enc:v1 values in the final state (the last step).

public long RemainingLegacyValues { get; set; }

Property Value​

Int64

Steps​

The steps in execution order.

public List<SecretSweepStepReportDto> Steps { get; set; }

Property Value​

List<SecretSweepStepReportDto>

SecretsToReEnter​

The secrets that were lost (unknown key id) and must be re-entered.

public List<SecretValueReferenceDto> SecretsToReEnter { get; set; }

Property Value​

List<SecretValueReferenceDto>

PlaceholdersNormalized​

Legacy clear-text placeholders (TODO_SET_*, <…>) converted once to "not set" over all steps (migration only; placeholders have no meaning on any write path).

public long PlaceholdersNormalized { get; set; }

Property Value​

Int64

SkippedLegacyV1KeyMissing​

SecretSweepModeDto.CleanupUnreadable only, summed over all steps: legacy enc:v1 values that were kept although unreadable, because only the legacy key (SecretEncryption:LegacyV1Key) is missing - a configuration gap, not key loss. They stay in SecretSweepReportDto.Unreadable (key id enc:v1) and become readable once the legacy key is configured.

public long SkippedLegacyV1KeyMissing { get; set; }

Property Value​

Int64

Unreadable​

Stored values that cannot be read because their key id is not in the key ring - the re-entry list (decision 2026-10-06). They are kept and become readable once the key is added to the ring; only re-entry or SecretSweepModeDto.CleanupUnreadable removes them.

public List<SecretUnreadableValueDto> Unreadable { get; set; }

Property Value​

List<SecretUnreadableValueDto>

Constructors​

SecretSweepReportDto()​

public SecretSweepReportDto()