RevealSecretNodeConfiguration
Namespace: Meshmakers.Octo.MeshAdapter.Nodes.Extract
Configuration of RevealSecret@1 (AB#5538): reads one Secret attribute of one runtime
entity, decrypts it in process and writes the plaintext to .
public record RevealSecretNodeConfiguration : TargetPathNodeConfiguration, INodeConfiguration, IEquatable<NodeConfiguration>, ITargetPathNodeConfiguration, IEquatable<TargetPathNodeConfiguration>, IEquatable<RevealSecretNodeConfiguration>
Inheritance Object → NodeConfiguration → TargetPathNodeConfiguration → RevealSecretNodeConfiguration
Implements INodeConfiguration, IEquatable<NodeConfiguration>, ITargetPathNodeConfiguration, IEquatable<TargetPathNodeConfiguration>, IEquatable<RevealSecretNodeConfiguration>
Remarks:
The only way for a pipeline to obtain the plaintext of a Secret attribute (concept AB#5528,
decision 6): every other node — GetRtEntitiesById@1, GetRtEntitiesByType@1, queries,
change streams — sees the marker {"isSet": true|false}. The decrypt is counted
(octo.secrets.decrypt{tenant,ckType,attribute,service}), the value is never logged, and the
written plaintext is registered as secret for the execution, so debug snapshots, the execution log
and SetPipelineExecutionResult@1 show *** instead.
A Secret that is not set (absent, null, empty or corrupt) writes null to the target. A
value whose key id is not in the adapter's key ring (e.g. after a restore from another environment)
is treated as not set as well: null plus an error in the execution log naming the key id. An
unknown entity, an attribute that is not a Secret, a host without key ring, strict-mode clear text or
a tampered value fail the node; no message carries the value.
Properties
Identity
Identity the entity is read as: Caller (default) or ServiceAccount (AB#5127). The
identity must be allowed to read the entity — data permissions apply to the read, decryption
itself needs no extra permission. System is refused: it bypasses data permissions, so it
would let anyone who may edit a pipeline reveal every credential of the tenant.
public NodeExecutionIdentity Identity { get; set; }
Property Value
NodeExecutionIdentity
CkTypeId
Runtime CK type of the entity (use either CkTypeId or CkTypeIdPath)
public RtCkId<CkTypeId> CkTypeId { get; set; }
Property Value
RtCkId<CkTypeId>
CkTypeIdPath
JSONPath to the runtime CK type id of the entity (alternative to CkTypeId)
public string CkTypeIdPath { get; set; }
Property Value
RtId
Runtime id of the entity (use either RtId or RtIdPath)
public Nullable<OctoObjectId> RtId { get; set; }
Property Value
RtIdPath
JSONPath to the runtime id of the entity (alternative to RtId; RtId wins when both are set)
public string RtIdPath { get; set; }
Property Value
AttributeName
Name of the Secret attribute, e.g. Password or password (case-insensitive). A
dotted path reaches a Secret inside single Record attributes (Settings.ApiKey);
record arrays are not supported.
public string AttributeName { get; set; }
Property Value
TargetPath
public string TargetPath { get; set; }
Property Value
TargetValueWriteMode
public TargetValueWriteModes TargetValueWriteMode { get; set; }
Property Value
TargetValueWriteModes
TargetValueKind
public ValueKinds TargetValueKind { get; set; }
Property Value
ValueKinds
DocumentMode
public DocumentModes DocumentMode { get; set; }
Property Value
DocumentModes
Description
public string Description { get; set; }
Property Value
Constructors
RevealSecretNodeConfiguration()
Caution
Constructors of types with required members are not supported in this version of your compiler.
public RevealSecretNodeConfiguration()