Zum Hauptinhalt springen

SecretSweepMode

Namespace: Meshmakers.Octo.Runtime.Contracts.Secrets

Mode of a secret sweep (concept §5.2).

public enum SecretSweepMode

Inheritance Object → ValueType → Enum → SecretSweepMode
Implements IComparable, ISpanFormattable, IFormattable, IConvertible

Fields​

NameValueDescription
Verify0Count only - nothing is decrypted or written. Recurring after the encrypt sweep; strict mode starts 14 days after it reports zero plaintext (decision 10). Needs no key material (AB#5532): it classifies by key id, so on a host without key ring (or without the legacy key) the protected values whose key id is not in the - possibly empty - ring and the enc:v1 strings are reported as SecretValueForm.UnknownKeyId and listed in SecretSweepResult.Unreadable (the re-entry list of a restore without keys). Clear text stays SecretValueForm.Plaintext.
Encrypt1Legacy values (clear text and enc:v1) become enc:v2 with the active key; legacy strings that are exactly a placeholder () or empty become null, once (SecretSweepResult.PlaceholdersNormalized). enc:v2 values stay as they are, whatever their key id; values with an unknown key id are kept and listed in SecretSweepResult.Unreadable. This is also the restore flow (Verify, then Encrypt).
Reprotect2Everything not protected with the active key (legacy and enc:v2 of another known key id) is re-encrypted with the active key - key rotation, and the optional ops step of an environment handover (source key added to the ring temporarily). Values with an unknown key id cannot be decrypted: they are kept and listed in SecretSweepResult.Unreadable.
CleanupUnreadable3ADMIN, HIGH RISK (replaces the former ClearUnknownKid, same numeric value): enc:v2 values whose key id is not in the key ring are DELETED (set to null, "not set") and listed in SecretSweepResult.Cleared. Requires SecretSweepOptions.ConfirmCleanupUnreadable. Without it such values are kept, read as "key missing" and become readable again once their key is added to the ring (decisions 2026-10-06, item 2) - only run it when the key is gone for good, and take a dump first. Callers gate it by role. A legacy enc:v1 string that is unreadable only because SecretEncryption:LegacyV1Key is not configured (key id SecretValueStates.LegacyV1KeyId) is NOT deleted - a configuration gap, recoverable by configuring the legacy key: it stays in SecretSweepResult.Unreadable and is counted in SecretSweepResult.SkippedLegacyV1KeyMissing.
Decrypt4EMERGENCY ONLY, ENGINE-INTERNAL (rollback after phase 4, concept §5.2): every decryptable value is written back as a clear-text string, so binaries without the Secret type can read it again. Requires SecretSweepOptions.ConfirmDecrypt. No API (system API, bot job, octo-cli, MCP) exposes this mode (decisions 2026-10-06, item 2: no decrypt / plaintext export through any API); it is reachable only by code running in the engine process. Treat the tenant as exposed afterwards and run SecretSweepMode.Encrypt as soon as the emergency is over.