SecretSweepResult
Namespace: Meshmakers.Octo.Runtime.Contracts.Secrets
Result of a secret sweep (concept §5.2, §5.3). Counts are the forms as FOUND, before the sweep acted on them; SecretSweepResult.ValuesRewritten says how many were changed.
public sealed class SecretSweepResult
Inheritance Object → SecretSweepResult
Properties
TenantId
Tenant that was swept.
public string TenantId { get; }
Property Value
Mode
Mode of the sweep.
public SecretSweepMode Mode { get; }
Property Value
StartedAt
Start (UTC).
public DateTime StartedAt { get; }
Property Value
CompletedAt
End (UTC); null while running.
public Nullable<DateTime> CompletedAt { get; set; }
Property Value
CkTypesScanned
CK types scanned (concrete types with at least one Secret slot).
public int CkTypesScanned { get; set; }
Property Value
EntitiesScanned
Entities read.
public long EntitiesScanned { get; set; }
Property Value
ArchivedEntitiesScanned
Entities among SecretSweepResult.EntitiesScanned that are archived (deleted, RtState.Archived;
AB#5532/AB#5544). The sweep processes their stored secrets like any other (encrypt, re-protect,
cleanup) so no clear text or unreadable leftovers stay at rest, and counts them in
SecretSweepResult.Totals / SecretSweepResult.Slots, but never lists them in SecretSweepResult.Unreadable or
SecretSweepResult.Cleared: a deleted entity is no re-entry task (see SecretSweepResult.ArchivedUnreadableValues).
public long ArchivedEntitiesScanned { get; set; }
Property Value
ArchivedUnreadableValues
Values with an unknown key id on archived entities (SecretSweepResult.ArchivedEntitiesScanned): kept, or deleted by SecretSweepMode.CleanupUnreadable, but not listed in SecretSweepResult.Unreadable / SecretSweepResult.Cleared (AB#5532/AB#5544). Counted in SecretFormCounts.UnknownKeyId as well.
public long ArchivedUnreadableValues { get; set; }
Property Value
EntitiesRewritten
Entities with at least one rewritten attribute.
public long EntitiesRewritten { get; set; }
Property Value
ValuesRewritten
Secret values changed (encrypted, re-protected, cleared, decrypted).
public long ValuesRewritten { get; set; }
Property Value
ValuesEncrypted
Values converted from legacy clear text or enc:v1 to enc:v2 and written in this run
(SecretSweepMode.Encrypt, SecretSweepMode.Reprotect; AB#5532). Included in
SecretSweepResult.ValuesRewritten; a conversion whose write did not happen (failure, concurrent
modification) is not counted. SecretSweepResult.Totals are the forms as FOUND, so they do not change
with this count - a follow-up SecretSweepMode.Verify describes the state after the run.
public long ValuesEncrypted { get; set; }
Property Value
Totals
Counts per form over the whole tenant.
public SecretFormCounts Totals { get; }
Property Value
Slots
Counts per CK type and Secret slot.
public List<SecretSlotReport> Slots { get; }
Property Value
Cleared
Values deleted by SecretSweepMode.CleanupUnreadable (an enc:v2 envelope with an
unknown key id) - these need re-entry. No other mode clears a value; normalised legacy placeholders
are not listed here, they were never set (see SecretSweepResult.PlaceholdersNormalized). Values deleted on
archived (deleted) entities are not listed either (SecretSweepResult.ArchivedUnreadableValues).
public List<SecretSweepClearedValue> Cleared { get; }
Property Value
Unreadable
Values whose key id is not in the key ring, found and KEPT by every mode except
SecretSweepMode.CleanupUnreadable (which lists them in SecretSweepResult.Cleared; it keeps
and lists here only the enc:v1 strings of a host without legacy key,
SecretSweepResult.SkippedLegacyV1KeyMissing) - the
re-entry list after a restore from another environment (decisions 2026-10-06, item 2). Counted in
SecretFormCounts.UnknownKeyId as well. Archived (deleted) entities are never listed
(SecretSweepResult.ArchivedUnreadableValues).
public List<SecretSweepUnreadableValue> Unreadable { get; }
Property Value
List<SecretSweepUnreadableValue>
PlaceholdersNormalized
Legacy strings in Secret slots that were exactly a placeholder (<...>, TODO_SET_...,
) or empty and were set to null
("not set") by SecretSweepMode.Encrypt,
SecretSweepMode.Reprotect or ISecretMaintenanceService.NormalizePlaceholdersAsync(String, String, CancellationToken).
Included in SecretSweepResult.ValuesRewritten.
public long PlaceholdersNormalized { get; set; }
Property Value
SkippedConcurrentlyModified
Attributes the sweep would have rewritten but left alone because their stored value changed after the sweep read it (conditional rewrite, AB#5532). Not a failure: the newer value was written by someone else and the next sweep processes it. Their changes are not counted in SecretSweepResult.ValuesRewritten.
public long SkippedConcurrentlyModified { get; set; }
Property Value
SkippedLegacyV1KeyMissing
SecretSweepMode.CleanupUnreadable only: legacy enc:v1 strings that were NOT deleted
although unreadable, because the only thing missing is the legacy key (SecretEncryption:LegacyV1Key)
- a configuration gap, not key loss (AB#5532). They stay in SecretSweepResult.Unreadable (key id SecretValueStates.LegacyV1KeyId) and become readable once the legacy key is configured.
public long SkippedLegacyV1KeyMissing { get; set; }
Property Value
Failures
Values that could not be processed.
public List<SecretSweepFailure> Failures { get; }
Property Value
Success
True when nothing failed.
public bool Success { get; }
Property Value
Constructors
SecretSweepResult(String, SecretSweepMode)
Creates a new result.
public SecretSweepResult(string tenantId, SecretSweepMode mode)
Parameters
tenantId String
mode SecretSweepMode