kindgi secrets
Manage per-environment secrets via the /v1/secrets/* wire.
kindgi secrets list
Section titled “kindgi secrets list”List secret metadata under --scope + --env. Never returns values.
kindgi secrets list --env=<name> --scope=<kind>[:id] [--include-revoked] [--name-prefix=<p>] [--cursor=<c>] [--limit=<n>]Flags:
--cursor <value>: Resume after this cursor, from the previous page'snextCursor.--env <value>: The environment the secret belongs to. Required; underkindgi dev,localis the pack's env files.--include-revoked: Include revoked secrets. Not applied yet: the API ignores it, so revoked secrets stay hidden.--limit <value>: The most secrets to return (default 25, at most 100).--name-prefix <value>: Only the secrets whose name starts with this prefix.--scope <value>: Where the secret lives:tenant,org:<orgId>orproject:<projectId>. Required.
kindgi secrets get
Section titled “kindgi secrets get”Fetch secret metadata (name + version + timestamps only, NEVER the value).
kindgi secrets get <NAME> --env=<name> --scope=<kind>[:id]Flags:
--env <value>: The environment the secret belongs to. Required; underkindgi dev,localis the pack's env files.--scope <value>: Where the secret lives:tenant,org:<orgId>orproject:<projectId>. Required.
kindgi secrets set
Section titled “kindgi secrets set”Write a new secret value. Default: interactive TTY prompt. Use --from-stdin | --from-file for automation.
kindgi secrets set <NAME> --env=<name> --scope=<kind>[:id] [--write-mode=create-new|add-version] [--from-stdin | --from-file <path>] [--rotation-due-at=<iso>] [--if-version=<n>]Flags:
--env <value>: The environment the secret belongs to. Required; underkindgi dev,localis the pack's env files.--from-file <value>: Read the value from this file instead of prompting. A file group or others can access is refused (chmod 600).--from-stdin: Read the secret's value from stdin instead of prompting.--if-version <value>: Write only if the secret is still at this version (0when it doesn't exist yet); otherwise fail with a conflict.--rotation-due-at <value>: When the secret is due for rotation, as an ISO 8601 timestamp; kept with its metadata.--scope <value>: Where the secret lives:tenant,org:<orgId>orproject:<projectId>. Required.--write-mode <value>:create-new(the default) refuses a secret that exists;add-versionwrites a new version, creating it if needed.
kindgi secrets rotate
Section titled “kindgi secrets rotate”Rotate a secret. Async providers polled to terminal; use --no-wait to bypass polling and return wire response.
kindgi secrets rotate <NAME> --env=<name> --scope=<kind>[:id] [--new-value | --from-stdin | --from-file <path>] [--revoke-old-after=<ms>] [--no-wait]Flags:
--env <value>: The environment the secret belongs to. Required; underkindgi dev,localis the pack's env files.--from-file <value>: Read the new value from this file. A file group or others can access is refused (chmod 600).--from-stdin: Read the new value from stdin.--new-value: Prompt for the new value (no echo). Without it,--from-stdinor--from-file, the secret store must rotate the value itself.--no-wait: Print the API's first response instead of waiting for an asynchronous rotation to finish.--revoke-old-after <value>: Revoke the old version this many milliseconds after the rotation (0: at once). Without it, the old version stays valid.--scope <value>: Where the secret lives:tenant,org:<orgId>orproject:<projectId>. Required.
kindgi secrets revoke
Section titled “kindgi secrets revoke”Revoke a secret. Default: soft (keeps audit tombstone). --hard: cryptographic erasure.
kindgi secrets revoke <NAME> --env=<name> --scope=<kind>[:id] [--hard] [--reason=<r>]Flags:
--env <value>: The environment the secret belongs to. Required; underkindgi dev,localis the pack's env files.--hard: Erase the value for good instead of keeping an audit tombstone. Cannot be undone.--reason <value>: Why the secret is revoked; kept on the record asrevokeReason.--scope <value>: Where the secret lives:tenant,org:<orgId>orproject:<projectId>. Required.
kindgi secrets pull
Section titled “kindgi secrets pull”Fetch secret metadata into .secrets/<envName>/manifest.json. Never fetches bytes.
kindgi secrets pull --env=<name> --scope=<kind>[:id] [--path <dir>]Flags:
--env <value>: The environment the secret belongs to. Required; underkindgi dev,localis the pack's env files.--path <value>: The pack directory to write.secrets/<env>/manifest.jsonunder (default: the current directory).--scope <value>: Where the secret lives:tenant,org:<orgId>orproject:<projectId>. Required.
Every command also takes the global flags.