SecretSweepReportDto
Namespace: Meshmakers.Octo.Communication.Contracts.DataTransferObjects
Report of the secret sweep of one tenant, as returned by bot-services
(GET {tenantId}/v1/jobs/secret-sweep/report, GET system/v1/secrets/reports; AB#5539).
Carries counts, CK type ids, runtime ids and attribute paths - never a value, never ciphertext.
public class SecretSweepReportDto
Inheritance Object → SecretSweepReportDto
Properties
TenantId
Tenant.
public string TenantId { get; set; }
Property Value
Mode
The requested mode. Writing modes are followed by a SecretSweepModeDto.Verify step that describes the state after the sweep.
public SecretSweepModeDto Mode { get; set; }
Property Value
Trigger
What started the sweep.
public SecretSweepTriggerDto Trigger { get; set; }
Property Value
Outcome
Outcome.
public SecretSweepOutcomeDto Outcome { get; set; }
Property Value
Reason
Why the sweep was skipped or failed, or a remark. Never contains a value.
public string Reason { get; set; }
Property Value
StartedAt
Start (UTC).
public DateTime StartedAt { get; set; }
Property Value
CompletedAt
End (UTC).
public DateTime CompletedAt { get; set; }
Property Value
BackupFileName
File name of the pre-sweep dump on the bot service, or null when none was taken.
public string BackupFileName { get; set; }
Property Value
ActiveKeyId
Active key id of the key ring at the time of the sweep, or null when no key is configured.
public string ActiveKeyId { get; set; }
Property Value
StrictModeActive
True when strict mode was in force for the environment.
public bool StrictModeActive { get; set; }
Property Value
StrictModeViolation
True when strict mode was in force and the final state still holds legacy values (clear text or
enc:v1).
public bool StrictModeViolation { get; set; }
Property Value
RemainingLegacyValues
Clear-text plus enc:v1 values in the final state (the last step).
public long RemainingLegacyValues { get; set; }
Property Value
Steps
The steps in execution order.
public List<SecretSweepStepReportDto> Steps { get; set; }
Property Value
List<SecretSweepStepReportDto>
SecretsToReEnter
The secrets that were lost (unknown key id) and must be re-entered.
public List<SecretValueReferenceDto> SecretsToReEnter { get; set; }
Property Value
PlaceholdersNormalized
Legacy clear-text placeholders (TODO_SET_*, <…>) converted once to "not set"
over all steps (migration only; placeholders have no meaning on any write path).
public long PlaceholdersNormalized { get; set; }
Property Value
SkippedLegacyV1KeyMissing
SecretSweepModeDto.CleanupUnreadable only, summed over all steps: legacy enc:v1
values that were kept although unreadable, because only the legacy key
(SecretEncryption:LegacyV1Key) is missing - a configuration gap, not key loss. They stay in
SecretSweepReportDto.Unreadable (key id enc:v1) and become readable once the legacy key is configured.
public long SkippedLegacyV1KeyMissing { get; set; }
Property Value
Unreadable
Stored values that cannot be read because their key id is not in the key ring - the re-entry list (decision 2026-10-06). They are kept and become readable once the key is added to the ring; only re-entry or SecretSweepModeDto.CleanupUnreadable removes them.
public List<SecretUnreadableValueDto> Unreadable { get; set; }
Property Value
List<SecretUnreadableValueDto>
Constructors
SecretSweepReportDto()
public SecretSweepReportDto()