Skip to content

kindgi secrets

Manage per-environment secrets via the /v1/secrets/* wire.

List secret metadata under --scope + --env. Never returns values.

Terminal window
kindgi secrets list --env=<name> --scope=<kind>[:id] [--include-revoked] [--name-prefix=<p>] [--cursor=<c>] [--limit=<n>]

Flags:

  • --cursor <value>: Resume after this cursor, from the previous page's nextCursor.
  • --env <value>: The environment the secret belongs to. Required; under kindgi dev, local is the pack's env files.
  • --include-revoked: Include revoked secrets. Not applied yet: the API ignores it, so revoked secrets stay hidden.
  • --limit <value>: The most secrets to return (default 25, at most 100).
  • --name-prefix <value>: Only the secrets whose name starts with this prefix.
  • --scope <value>: Where the secret lives: tenant, org:&lt;orgId&gt; or project:&lt;projectId&gt;. Required.

Fetch secret metadata (name + version + timestamps only, NEVER the value).

Terminal window
kindgi secrets get <NAME> --env=<name> --scope=<kind>[:id]

Flags:

  • --env <value>: The environment the secret belongs to. Required; under kindgi dev, local is the pack's env files.
  • --scope <value>: Where the secret lives: tenant, org:&lt;orgId&gt; or project:&lt;projectId&gt;. Required.

Write a new secret value. Default: interactive TTY prompt. Use --from-stdin | --from-file for automation.

Terminal window
kindgi secrets set <NAME> --env=<name> --scope=<kind>[:id] [--write-mode=create-new|add-version] [--from-stdin | --from-file <path>] [--rotation-due-at=<iso>] [--if-version=<n>]

Flags:

  • --env <value>: The environment the secret belongs to. Required; under kindgi dev, local is the pack's env files.
  • --from-file <value>: Read the value from this file instead of prompting. A file group or others can access is refused (chmod 600).
  • --from-stdin: Read the secret's value from stdin instead of prompting.
  • --if-version <value>: Write only if the secret is still at this version (0 when it doesn't exist yet); otherwise fail with a conflict.
  • --rotation-due-at <value>: When the secret is due for rotation, as an ISO 8601 timestamp; kept with its metadata.
  • --scope <value>: Where the secret lives: tenant, org:&lt;orgId&gt; or project:&lt;projectId&gt;. Required.
  • --write-mode <value>: create-new (the default) refuses a secret that exists; add-version writes a new version, creating it if needed.

Rotate a secret. Async providers polled to terminal; use --no-wait to bypass polling and return wire response.

Terminal window
kindgi secrets rotate <NAME> --env=<name> --scope=<kind>[:id] [--new-value | --from-stdin | --from-file <path>] [--revoke-old-after=<ms>] [--no-wait]

Flags:

  • --env <value>: The environment the secret belongs to. Required; under kindgi dev, local is the pack's env files.
  • --from-file <value>: Read the new value from this file. A file group or others can access is refused (chmod 600).
  • --from-stdin: Read the new value from stdin.
  • --new-value: Prompt for the new value (no echo). Without it, --from-stdin or --from-file, the secret store must rotate the value itself.
  • --no-wait: Print the API's first response instead of waiting for an asynchronous rotation to finish.
  • --revoke-old-after <value>: Revoke the old version this many milliseconds after the rotation (0: at once). Without it, the old version stays valid.
  • --scope <value>: Where the secret lives: tenant, org:&lt;orgId&gt; or project:&lt;projectId&gt;. Required.

Revoke a secret. Default: soft (keeps audit tombstone). --hard: cryptographic erasure.

Terminal window
kindgi secrets revoke <NAME> --env=<name> --scope=<kind>[:id] [--hard] [--reason=<r>]

Flags:

  • --env <value>: The environment the secret belongs to. Required; under kindgi dev, local is the pack's env files.
  • --hard: Erase the value for good instead of keeping an audit tombstone. Cannot be undone.
  • --reason <value>: Why the secret is revoked; kept on the record as revokeReason.
  • --scope <value>: Where the secret lives: tenant, org:&lt;orgId&gt; or project:&lt;projectId&gt;. Required.

Fetch secret metadata into .secrets/<envName>/manifest.json. Never fetches bytes.

Terminal window
kindgi secrets pull --env=<name> --scope=<kind>[:id] [--path <dir>]

Flags:

  • --env <value>: The environment the secret belongs to. Required; under kindgi dev, local is the pack's env files.
  • --path <value>: The pack directory to write .secrets/&lt;env&gt;/manifest.json under (default: the current directory).
  • --scope <value>: Where the secret lives: tenant, org:&lt;orgId&gt; or project:&lt;projectId&gt;. Required.

Every command also takes the global flags.