ISecretInventoryService
Namespace: Meshmakers.Octo.Runtime.Contracts.Secrets
Secrets overview of a tenant (AB#5532, handover §7 "Q1"): every Secret slot of every entity -
top-level attributes and record members at any depth - with its storage form, key id, "set at" and
whether it needs re-entry. Never returns a value or ciphertext. Implemented in Runtime.Engine
(SecretInventoryService) over the same scan as the secret sweep and registered by
AddRuntimeEngine(); the asset repository exposes it as GraphQL secrets { inventory summary }.
public interface ISecretInventoryService
Remarks:
Both calls scan the tenant's entities with Secret slots; archived (deleted, RtState.Archived)
entities are excluded exactly like in the public queries (AB#5532/AB#5544). Results are live, not
cached. Works without keys: without a key ring every protected value is reported as
SecretStorageForm.KeyMissing (the key id is not in this host's - empty - ring).
Methods
ListAsync(String, SecretInventoryQuery, CancellationToken)
Lists Secret slots, filtered and paged. Order: CK type (full name), rtId, attribute order of the type, record elements in stored order.
Task<SecretInventoryPage> ListAsync(string tenantId, SecretInventoryQuery query, CancellationToken cancellationToken)
Parameters
tenantId String
Tenant
query SecretInventoryQuery
Filters and paging
cancellationToken CancellationToken
Cancellation token
Returns
Task<SecretInventoryPage>
The requested page and the total number of matching slots
SummarizeAsync(String, CancellationToken)
Counts all Secret slots of the tenant per storage form.
Task<SecretInventorySummary> SummarizeAsync(string tenantId, CancellationToken cancellationToken)
Parameters
tenantId String
Tenant
cancellationToken CancellationToken
Cancellation token
Returns
Task<SecretInventorySummary>
The counts