Skip to main content

ISecretInventoryService

Namespace: Meshmakers.Octo.Runtime.Contracts.Secrets

Secrets overview of a tenant (AB#5532, handover §7 "Q1"): every Secret slot of every entity - top-level attributes and record members at any depth - with its storage form, key id, "set at" and whether it needs re-entry. Never returns a value or ciphertext. Implemented in Runtime.Engine (SecretInventoryService) over the same scan as the secret sweep and registered by AddRuntimeEngine(); the asset repository exposes it as GraphQL secrets { inventory summary }.

public interface ISecretInventoryService

Remarks:

Both calls scan the tenant's entities with Secret slots; archived (deleted, RtState.Archived) entities are excluded exactly like in the public queries (AB#5532/AB#5544). Results are live, not cached. Works without keys: without a key ring every protected value is reported as SecretStorageForm.KeyMissing (the key id is not in this host's - empty - ring).

Methods​

ListAsync(String, SecretInventoryQuery, CancellationToken)​

Lists Secret slots, filtered and paged. Order: CK type (full name), rtId, attribute order of the type, record elements in stored order.

Task<SecretInventoryPage> ListAsync(string tenantId, SecretInventoryQuery query, CancellationToken cancellationToken)

Parameters​

tenantId String
Tenant

query SecretInventoryQuery
Filters and paging

cancellationToken CancellationToken
Cancellation token

Returns​

Task<SecretInventoryPage>
The requested page and the total number of matching slots

SummarizeAsync(String, CancellationToken)​

Counts all Secret slots of the tenant per storage form.

Task<SecretInventorySummary> SummarizeAsync(string tenantId, CancellationToken cancellationToken)

Parameters​

tenantId String
Tenant

cancellationToken CancellationToken
Cancellation token

Returns​

Task<SecretInventorySummary>
The counts