SecretStatus
Shows the encryption status of Secret attributes: environment status (key ring, active and known key ids, strict mode, recurring Verify), recent sweep runs with their dump state and the last sweep report (counts per form and key id, unreadable secrets to re-enter). Never shows secret values.
Examples
Report of the context tenant:
octo-cli -c SecretStatus
Report of a specific tenant:
octo-cli -c SecretStatus -tid "mytenant"
One line per tenant (run against the system tenant):
octo-cli -c SecretStatus -a
All reports as JSON, e.g. for monitoring scripts:
octo-cli -c SecretStatus -a -j
Options
| Short | Long | Required | Description |
|---|---|---|---|
-tid | --tenantId | no | Tenant to report on (default: tenant of the context) |
-a | --all | no | Show the last report of every tenant (system API, requires system tenant rights) |
-j | --json | no | Output as JSON (tenant: environment, recentRuns, report; -a: the reports) |
Notes
Tenant mode prints the environment status (key ring configured, active and known key ids, legacy enc:v1 key, strict mode and since when, recurring Verify cron, this tenant's last Verify), the last 10 sweep runs with the state of their pre-sweep dump, and the last report.
Shows the last report the bot service stored (recurring Verify sweep, a manual ReprotectSecrets run or the sweep after a restore). Run ReprotectSecrets -m Verify -w for a fresh one.
Forms: notSet, plaintext, encV1 (legacy key) and encV2 per key id; unknownKeyId means the value is stored encrypted with a key that is not in the key ring (unreadable, listed as a re-entry task). It becomes readable again when that key is added to the key ring.
Unreadable secrets are removed only by re-entry or ReprotectSecrets -m CleanupUnreadable -y; a pre-sweep dump can be deleted early with DeleteSecretSweepDump or restored with RestoreSecretSweepDump.
"Key ids needed by encrypted dumps" lists the key ids every encrypted dump still needs; DumpKeyMissing warns when one of them is no longer in the key ring (the dump can then neither be restored nor downloaded).