Skip to main content

RevealSecret@1

Node RevealSecret@1 decrypts one named Secret attribute of a runtime entity and writes the plaintext into the DataContext, so that following nodes can use it (for example to authenticate against an external system).

Availability

Available from System CK model 2.5.0 and the mesh adapter release that ships the Secret value type. The node is part of the mesh adapter's generated pipeline-schema.json.

Why a Separate Node​

Reading entities with GetRtEntitiesById@1, GetRtEntitiesByType@1 or GetRtEntitiesByWellKnownName@1 never returns the value of a Secret attribute — only the marker { "isSet": true|false }. A pipeline that needs the value must ask for it explicitly with RevealSecret@1:

  • Privileged: the node decrypts inside the mesh adapter process. No public API is involved, and no public API offers decryption.
  • One attribute per node: the configuration names the entity, its type and the attribute. There is no wildcard.
  • Counted: every decryption increments the metric octo.secrets.decrypt.
  • Never logged: the value does not appear in logs. Revealed values are masked as *** in debug snapshots, dry-run output, execution results, node error messages and stored execution errors. Debug snapshots list the masked locations in redactedPaths (JSONPaths rooted at the snapshot, e.g. $.output.smtp.password; a value masked inside a longer string is listed with the path of that string), so the Studio marks exactly these paths.

Adapter Prerequisites​

  • Mesh Adapter
  • The mesh adapter must receive the secret encryption key ring (workload flag ReceivesClusterSecrets, see Secret Encryption Key Ring). Without it the node fails with a configuration error.

Node Configuration​

For fields targetPath, targetValueWriteMode and targetValueKind, see Overview.

transformations:
- type: RevealSecret@1
ckTypeId: System.Communication/EMailSenderConfiguration
rtIdPath: $.config.rtId
attributeName: Password
targetPath: $.smtp.password
identity: ServiceAccount

Parameters​

ParameterTypeRequired / defaultDescription
attributeNameStringRequiredSecret attribute to decrypt, case-insensitive. A dotted path is allowed only through single Record attributes (Connection.Password); record arrays are refused
ckTypeIdRtCkIdOne of ckTypeId / ckTypeIdPathConstruction Kit type id of the entity
ckTypeIdPathString (JSONPath)Path to the CK type id in the DataContext
rtIdString (24-hex object id)One of rtId / rtIdPathRuntime id of the entity. Wins over rtIdPath
rtIdPathString (JSONPath)Path to the runtime id in the DataContext
targetPathString (JSONPath)$Where the plaintext is written
targetValueWriteModeEnumOverwriteSee Overview
targetValueKindEnumSimpleSee Overview
documentModeEnumExtendHow the result is merged into the DataContext document
identityCaller | ServiceAccountCallerIdentity the entity is read as. System is refused by the node
descriptionStringOptionalFree text

Schema groups in the Studio editor: Entity (ckTypeId, ckTypeIdPath, rtId, rtIdPath), Secret (attributeName), Paths, Write Mode, Execution (identity), General (description).

Behaviour​

  • If the attribute is not set, the target receives null.
  • If the entity does not exist, or the attribute is not of value type Secret, the node fails.
  • If the stored value was encrypted with a key id the adapter's key ring does not contain (keyMissing, e.g. after a restore from another environment), it is treated as not set: the node writes null and logs an error without the value. Enter the value again or add the key to the ring (see Unreadable secrets).
  • If strict mode is on and the value is still stored as clear text, the node fails; run the encrypt sweep or enter the value again.
  • Type-switching nodes (ConvertDataType, SetPrimitiveValue, If, Switch, ExecuteCSharp, DataMapping) fail with "Secret not supported" on a secret marker; reading <path>.isSet as a Boolean works.
  • GetPipelineConfigByWellKnownName@1 and GetPipelineConfigByCkTypeId@1 mask the Secret attributes of the configuration they copy.
  • Keep the plaintext in the DataContext only as long as needed. Do not write it into entities, archives, notifications or HTTP responses.

Example​

Resolve a configuration entity by its well-known name, reveal its client secret, and use it for an HTTP request:

transformations:
- type: GetRtEntitiesByWellKnownName@1
ckTypeId: System.Communication/FinApiConfiguration
wellKnownNamePath: $.configurationName # e.g. "FinApi" in the incoming payload
rtIdTargetPath: $.configurationRtId
- type: RevealSecret@1
rtIdPath: $.configurationRtId
ckTypeId: System.Communication/FinApiConfiguration
attributeName: ClientSecret
targetPath: $.secrets.clientSecret
identity: ServiceAccount
- type: MakeHttpRequest@1
# ... uses $.secrets.clientSecret

See Also​