RestoreSecretSweepDump
Restores the pre-sweep dump of a secret sweep run into the same tenant, replacing its data (requires SecretManagement). Use -y to skip confirmation, -w to wait.
Examples
Roll a tenant back to the state before a sweep and wait for the restore:
octo-cli -c RestoreSecretSweepDump `
-tid "mytenant" `
-r "1234" `
-w
Options
| Short | Long | Required | Description |
|---|---|---|---|
-tid | --tenantId | no | Tenant of the sweep run; the dump is restored into it (default: tenant of the context) |
-r | --runId | yes | Id of the sweep run whose pre-sweep dump is restored (see SecretStatus) |
-y | --yes | no | Skip confirmation prompt |
-w | --wait | no | Wait for a import job to complete |
Notes
The tenant's database is dropped and replaced by the dump; all changes since the sweep run are lost. A Verify runs after the restore.
A dump taken before the first Encrypt contains plaintext secrets: restoring it brings the plaintext back. Run 'ReprotectSecrets -m Encrypt' afterwards.
Refused when the dump was deleted or expired, no longer exists, or is encrypted with a key id that is not in the key ring (DumpKeyMissing; SecretStatus lists the key ids the dumps need).
Without -w the command prints the job id and returns.