Zum Hauptinhalt springen

SecretSweepResult

Namespace: Meshmakers.Octo.Runtime.Contracts.Secrets

Result of a secret sweep (concept §5.2, §5.3). Counts are the forms as FOUND, before the sweep acted on them; SecretSweepResult.ValuesRewritten says how many were changed.

public sealed class SecretSweepResult

Inheritance Object → SecretSweepResult

Properties​

TenantId​

Tenant that was swept.

public string TenantId { get; }

Property Value​

String

Mode​

Mode of the sweep.

public SecretSweepMode Mode { get; }

Property Value​

SecretSweepMode

StartedAt​

Start (UTC).

public DateTime StartedAt { get; }

Property Value​

DateTime

CompletedAt​

End (UTC); null while running.

public Nullable<DateTime> CompletedAt { get; set; }

Property Value​

Nullable<DateTime>

CkTypesScanned​

CK types scanned (concrete types with at least one Secret slot).

public int CkTypesScanned { get; set; }

Property Value​

Int32

EntitiesScanned​

Entities read.

public long EntitiesScanned { get; set; }

Property Value​

Int64

ArchivedEntitiesScanned​

Entities among SecretSweepResult.EntitiesScanned that are archived (deleted, RtState.Archived; AB#5532/AB#5544). The sweep processes their stored secrets like any other (encrypt, re-protect, cleanup) so no clear text or unreadable leftovers stay at rest, and counts them in SecretSweepResult.Totals / SecretSweepResult.Slots, but never lists them in SecretSweepResult.Unreadable or SecretSweepResult.Cleared: a deleted entity is no re-entry task (see SecretSweepResult.ArchivedUnreadableValues).

public long ArchivedEntitiesScanned { get; set; }

Property Value​

Int64

ArchivedUnreadableValues​

Values with an unknown key id on archived entities (SecretSweepResult.ArchivedEntitiesScanned): kept, or deleted by SecretSweepMode.CleanupUnreadable, but not listed in SecretSweepResult.Unreadable / SecretSweepResult.Cleared (AB#5532/AB#5544). Counted in SecretFormCounts.UnknownKeyId as well.

public long ArchivedUnreadableValues { get; set; }

Property Value​

Int64

EntitiesRewritten​

Entities with at least one rewritten attribute.

public long EntitiesRewritten { get; set; }

Property Value​

Int64

ValuesRewritten​

Secret values changed (encrypted, re-protected, cleared, decrypted).

public long ValuesRewritten { get; set; }

Property Value​

Int64

ValuesEncrypted​

Values converted from legacy clear text or enc:v1 to enc:v2 and written in this run (SecretSweepMode.Encrypt, SecretSweepMode.Reprotect; AB#5532). Included in SecretSweepResult.ValuesRewritten; a conversion whose write did not happen (failure, concurrent modification) is not counted. SecretSweepResult.Totals are the forms as FOUND, so they do not change with this count - a follow-up SecretSweepMode.Verify describes the state after the run.

public long ValuesEncrypted { get; set; }

Property Value​

Int64

Totals​

Counts per form over the whole tenant.

public SecretFormCounts Totals { get; }

Property Value​

SecretFormCounts

Slots​

Counts per CK type and Secret slot.

public List<SecretSlotReport> Slots { get; }

Property Value​

List<SecretSlotReport>

Cleared​

Values deleted by SecretSweepMode.CleanupUnreadable (an enc:v2 envelope with an unknown key id) - these need re-entry. No other mode clears a value; normalised legacy placeholders are not listed here, they were never set (see SecretSweepResult.PlaceholdersNormalized). Values deleted on archived (deleted) entities are not listed either (SecretSweepResult.ArchivedUnreadableValues).

public List<SecretSweepClearedValue> Cleared { get; }

Property Value​

List<SecretSweepClearedValue>

Unreadable​

Values whose key id is not in the key ring, found and KEPT by every mode except SecretSweepMode.CleanupUnreadable (which lists them in SecretSweepResult.Cleared; it keeps and lists here only the enc:v1 strings of a host without legacy key, SecretSweepResult.SkippedLegacyV1KeyMissing) - the re-entry list after a restore from another environment (decisions 2026-10-06, item 2). Counted in SecretFormCounts.UnknownKeyId as well. Archived (deleted) entities are never listed (SecretSweepResult.ArchivedUnreadableValues).

public List<SecretSweepUnreadableValue> Unreadable { get; }

Property Value​

List<SecretSweepUnreadableValue>

PlaceholdersNormalized​

Legacy strings in Secret slots that were exactly a placeholder (<...>, TODO_SET_..., ) or empty and were set to null ("not set") by SecretSweepMode.Encrypt, SecretSweepMode.Reprotect or ISecretMaintenanceService.NormalizePlaceholdersAsync(String, String, CancellationToken). Included in SecretSweepResult.ValuesRewritten.

public long PlaceholdersNormalized { get; set; }

Property Value​

Int64

SkippedConcurrentlyModified​

Attributes the sweep would have rewritten but left alone because their stored value changed after the sweep read it (conditional rewrite, AB#5532). Not a failure: the newer value was written by someone else and the next sweep processes it. Their changes are not counted in SecretSweepResult.ValuesRewritten.

public long SkippedConcurrentlyModified { get; set; }

Property Value​

Int64

SkippedLegacyV1KeyMissing​

SecretSweepMode.CleanupUnreadable only: legacy enc:v1 strings that were NOT deleted although unreadable, because the only thing missing is the legacy key (SecretEncryption:LegacyV1Key)

public long SkippedLegacyV1KeyMissing { get; set; }

Property Value​

Int64

Failures​

Values that could not be processed.

public List<SecretSweepFailure> Failures { get; }

Property Value​

List<SecretSweepFailure>

Success​

True when nothing failed.

public bool Success { get; }

Property Value​

Boolean

Constructors​

SecretSweepResult(String, SecretSweepMode)​

Creates a new result.

public SecretSweepResult(string tenantId, SecretSweepMode mode)

Parameters​

tenantId String

mode SecretSweepMode