RevealSecret@1
Node RevealSecret@1 decrypts one named Secret attribute of a runtime entity and writes the plaintext into the DataContext, so that following nodes can use it (for example to authenticate against an external system).
Available from System CK model 2.5.0 and the mesh adapter release that ships the Secret value type. The node is part of the mesh adapter's generated pipeline-schema.json.
Why a Separate Node
Reading entities with GetRtEntitiesById@1, GetRtEntitiesByType@1 or GetRtEntitiesByWellKnownName@1 never returns the value of a Secret attribute — only the marker { "isSet": true|false }. A pipeline that needs the value must ask for it explicitly with RevealSecret@1:
- Privileged: the node decrypts inside the mesh adapter process. No public API is involved, and no public API offers decryption.
- One attribute per node: the configuration names the entity, its type and the attribute. There is no wildcard.
- Counted: every decryption increments the metric
octo.secrets.decrypt. - Never logged: the value does not appear in logs. Revealed values are masked as
***in debug snapshots, dry-run output, execution results, node error messages and stored execution errors. Debug snapshots list the masked locations inredactedPaths(JSONPaths rooted at the snapshot, e.g.$.output.smtp.password; a value masked inside a longer string is listed with the path of that string), so the Studio marks exactly these paths.
Adapter Prerequisites
- Mesh Adapter
- The mesh adapter must receive the secret encryption key ring (workload flag
ReceivesClusterSecrets, see Secret Encryption Key Ring). Without it the node fails with a configuration error.
Node Configuration
For fields targetPath, targetValueWriteMode and targetValueKind, see Overview.
transformations:
- type: RevealSecret@1
ckTypeId: System.Communication/EMailSenderConfiguration
rtIdPath: $.config.rtId
attributeName: Password
targetPath: $.smtp.password
identity: ServiceAccount
Parameters
| Parameter | Type | Required / default | Description |
|---|---|---|---|
attributeName | String | Required | Secret attribute to decrypt, case-insensitive. A dotted path is allowed only through single Record attributes (Connection.Password); record arrays are refused |
ckTypeId | RtCkId | One of ckTypeId / ckTypeIdPath | Construction Kit type id of the entity |
ckTypeIdPath | String (JSONPath) | Path to the CK type id in the DataContext | |
rtId | String (24-hex object id) | One of rtId / rtIdPath | Runtime id of the entity. Wins over rtIdPath |
rtIdPath | String (JSONPath) | Path to the runtime id in the DataContext | |
targetPath | String (JSONPath) | $ | Where the plaintext is written |
targetValueWriteMode | Enum | Overwrite | See Overview |
targetValueKind | Enum | Simple | See Overview |
documentMode | Enum | Extend | How the result is merged into the DataContext document |
identity | Caller | ServiceAccount | Caller | Identity the entity is read as. System is refused by the node |
description | String | Optional | Free text |
Schema groups in the Studio editor: Entity (ckTypeId, ckTypeIdPath, rtId, rtIdPath), Secret (attributeName), Paths, Write Mode, Execution (identity), General (description).
Behaviour
- If the attribute is not set, the target receives
null. - If the entity does not exist, or the attribute is not of value type
Secret, the node fails. - If the stored value was encrypted with a key id the adapter's key ring does not contain (
keyMissing, e.g. after a restore from another environment), it is treated as not set: the node writesnulland logs an error without the value. Enter the value again or add the key to the ring (see Unreadable secrets). - If strict mode is on and the value is still stored as clear text, the node fails; run the encrypt sweep or enter the value again.
- Type-switching nodes (
ConvertDataType,SetPrimitiveValue,If,Switch,ExecuteCSharp,DataMapping) fail with "Secret not supported" on a secret marker; reading<path>.isSetas a Boolean works. GetPipelineConfigByWellKnownName@1andGetPipelineConfigByCkTypeId@1mask the Secret attributes of the configuration they copy.- Keep the plaintext in the DataContext only as long as needed. Do not write it into entities, archives, notifications or HTTP responses.
Example
Resolve a configuration entity by its well-known name, reveal its client secret, and use it for an HTTP request:
transformations:
- type: GetRtEntitiesByWellKnownName@1
ckTypeId: System.Communication/FinApiConfiguration
wellKnownNamePath: $.configurationName # e.g. "FinApi" in the incoming payload
rtIdTargetPath: $.configurationRtId
- type: RevealSecret@1
rtIdPath: $.configurationRtId
ckTypeId: System.Communication/FinApiConfiguration
attributeName: ClientSecret
targetPath: $.secrets.clientSecret
identity: ServiceAccount
- type: MakeHttpRequest@1
# ... uses $.secrets.clientSecret