SecretEnvironmentStatusDto
Namespace: Meshmakers.Octo.Communication.Contracts.DataTransferObjects
Encryption status of the environment as seen from one tenant (bot services
GET {tenantId}/v1/secrets/status, AB#5528/AB#5544). Environment-level and identical in every
tenant except SecretEnvironmentStatusDto.LastVerifyAt. Never contains key material.
public class SecretEnvironmentStatusDto
Inheritance Object → SecretEnvironmentStatusDto
Properties
KeyRingConfigured
false: no key ring is configured - secret inputs are disabled, writes would fail with
SecretEncryptionNotConfigured.
public bool KeyRingConfigured { get; set; }
Property Value
ActiveKeyId
Key id new values are encrypted with; null when not configured.
public string ActiveKeyId { get; set; }
Property Value
KnownKeyIds
All key ids of the key ring.
public List<string> KnownKeyIds { get; set; }
Property Value
LegacyV1KeyConfigured
True when the legacy enc:v1 key is configured (to read legacy values).
public bool LegacyV1KeyConfigured { get; set; }
Property Value
StrictMode
True when strict mode is in force (legacy clear text / enc:v1 no longer accepted).
public bool StrictMode { get; set; }
Property Value
StrictModeSince
When strict mode is scheduled / became active (UTC), or null.
public Nullable<DateTime> StrictModeSince { get; set; }
Property Value
RecurringVerifyCron
Cron expression of the recurring Verify sweep; null when disabled.
public string RecurringVerifyCron { get; set; }
Property Value
LastVerifyAt
This tenant's last Verify run (UTC), null if none.
public Nullable<DateTime> LastVerifyAt { get; set; }
Property Value
Warnings
Warning codes about the environment (JSON warnings, AB#5534); empty when there is nothing to
warn about. Known codes: SecretEnvironmentWarningCodes. Clients show unknown codes as
a generic warning.
public List<string> Warnings { get; set; }
Property Value
RequiredKeyIds
Key ids of all encrypted (.octoenc) dumps currently held by bot services for this instance
(pre-sweep dumps, tenant dumps, staged restore uploads), read from their clear-text headers (JSON
requiredKeyIds, AB#5559). Every one of them must stay in the key ring until the newest dump
encrypted with it has expired; a missing one is reported as
SecretEnvironmentWarningCodes.DumpKeyMissing. Empty when there are no encrypted dumps or
the service is older than AB#5559. Never key material.
public List<string> RequiredKeyIds { get; set; }
Property Value
Constructors
SecretEnvironmentStatusDto()
public SecretEnvironmentStatusDto()