Skip to main content

SecretStatus

Shows the encryption status of Secret attributes: environment status (key ring, active and known key ids, strict mode, recurring Verify), recent sweep runs with their dump state and the last sweep report (counts per form and key id, unreadable secrets to re-enter). Never shows secret values.

Examples​

Report of the context tenant:

octo-cli -c SecretStatus

Report of a specific tenant:

octo-cli -c SecretStatus -tid "mytenant"

One line per tenant (run against the system tenant):

octo-cli -c SecretStatus -a

All reports as JSON, e.g. for monitoring scripts:

octo-cli -c SecretStatus -a -j

Options​

ShortLongRequiredDescription
-tid--tenantIdnoTenant to report on (default: tenant of the context)
-a--allnoShow the last report of every tenant (system API, requires system tenant rights)
-j--jsonnoOutput as JSON (tenant: environment, recentRuns, report; -a: the reports)

Notes​

Tenant mode prints the environment status (key ring configured, active and known key ids, legacy enc:v1 key, strict mode and since when, recurring Verify cron, this tenant's last Verify), the last 10 sweep runs with the state of their pre-sweep dump, and the last report.

Shows the last report the bot service stored (recurring Verify sweep, a manual ReprotectSecrets run or the sweep after a restore). Run ReprotectSecrets -m Verify -w for a fresh one.

Forms: notSet, plaintext, encV1 (legacy key) and encV2 per key id; unknownKeyId means the value is stored encrypted with a key that is not in the key ring (unreadable, listed as a re-entry task). It becomes readable again when that key is added to the key ring.

Unreadable secrets are removed only by re-entry or ReprotectSecrets -m CleanupUnreadable -y; a pre-sweep dump can be deleted early with DeleteSecretSweepDump or restored with RestoreSecretSweepDump.

"Key ids needed by encrypted dumps" lists the key ids every encrypted dump still needs; DumpKeyMissing warns when one of them is no longer in the key ring (the dump can then neither be restored nor downloaded).