Skip to main content

ReprotectSecrets

Starts a secret sweep job: re-encrypts all Secret attributes with the active key (Reprotect, default), encrypts remaining legacy values (Encrypt), removes values whose key id is not in the key ring (CleanupUnreadable, requires -y) or only counts them (Verify). Use -w to wait, -y to skip confirmation.

Examples​

Re-protect the context tenant after a key rotation and wait for the report:

octo-cli -c ReprotectSecrets -w

Count the forms of all secrets of a tenant (read-only, no confirmation):

octo-cli -c ReprotectSecrets `
-tid "mytenant" `
-m "Verify" `
-w

Encrypt remaining plaintext / enc:v1 values in all tenants (CI/CD):

octo-cli -c ReprotectSecrets `
-a `
-m "Encrypt" `
-y

Remove secrets that cannot be read with this key ring (after a restore, once they were re-entered or are not needed):

octo-cli -c ReprotectSecrets `
-tid "mytenant" `
-m "CleanupUnreadable" `
-y `
-w

Options​

ShortLongRequiredDescription
-tid--tenantIdnoTenant to sweep (default: tenant of the context)
-a--allnoSweep all tenants (system API, requires system tenant rights)
-m--modenoSweep mode: Reprotect (default), Encrypt, CleanupUnreadable or Verify
-y--yesnoSkip confirmation prompt
-w--waitnoWait for a import job to complete

Notes​

Writing modes (Reprotect, Encrypt, CleanupUnreadable) take a pre-sweep dump in the bot service and ask for confirmation; -y skips it. The CLI sends confirm=true to the bot service once confirmed.

CleanupUnreadable permanently removes secrets whose key id is not in the key ring (e.g. after a restore from another environment) and requires -y; recoverable only from the pre-sweep dump. SecretStatus lists these secrets as unreadable (re-entry tasks) before.

Restore with the source environment's key: add the key id to the key ring, then run Reprotect to move the values to the active key, then remove the source key.

Decrypt (writes clear text back) is an emergency operation and is not available in the CLI.

Without -w the command prints the job id and returns; follow up with SecretStatus.