delonix secret
Cofre de segredos cifrado em repouso — o produtor do `run --secret`.
Encrypted-at-rest secret vault — the source behind `run --secret`.
Um cofre local (SecretStore) cifrado com XChaCha20-Poly1305. Os valores
NUNCA são impressos por omissão (redigidos; --reveal é opt-in). É a fonte dos
container run --secret/--secret-files e do --password-secret do
volume create — o segredo entra uma vez, nunca fica no histórico do shell nem no manifesto.
A local vault (SecretStore) encrypted with XChaCha20-Poly1305.
Values are NEVER printed by default (redacted; --reveal is opt-in). It's the source
for container run --secret/--secret-files and volume create's
--password-secret — the secret goes in once, and never ends up in shell history or in
the manifest.
📄 Implementação real em Rust: cmd/secret.rs
Usage: delonix secret [OPTIONS] <COMMAND>
Commands:
create Create a secret from literals and/or a `.env` file
rm Remove a secret
inspect Show the keys of a secret (values redacted, unless `--reveal`)
ls List the secrets (name + number of keys; values NEVER shown)
set Set/update keys in a secret (creates it if it does not exist)
unset Remove a key from a secret (or the whole secret with `--all`)
apply Apply the `kind: Secret` documents from a manifest
rotate Rotate one key's VALUE to a fresh random one
rotate-key Rotate the host master key: re-encrypt ALL secrets with a new key. The values are preserved
help Print this message or the help of the given subcommand(s)
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
COMMAND MAP:
Lifecycle create · rm
Inspect ls · inspect
Configure set · unset
Declarative apply
Maintenance rotate · rotate-key
EXAMPLES:
# what exists — names and key counts; the values are never printed
delonix secret ls
# create one without the value ever reaching argv or the shell history
printf 'PASSWORD=s3cr3t\n' | delonix secret create db-pass --from-env-file -
# hand it to a container, decrypted only at spawn — the registry keeps the
# name, never the value
delonix container run -d --secret db-pass postgres:16
SEE ALSO:
delonix secret create · delonix secret ls · delonix container run · delonix
stack apply
delonix › secretsecret apply
Apply the kind: Secret documents from a manifest.
Declarative — creates the secret without needing secret create on the CLI.
Usage: delonix secret apply [OPTIONS]
Options:
-f, --file <FILE>
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# create the `kind: Secret` documents of the manifest in this directory
delonix secret apply
# from a file of your own, so the vault is provisioned from git like
# everything else
delonix secret apply -f examples/secret.yaml
SEE ALSO:
delonix secret create · delonix stack apply · delonix manifest schema
delonix › secret › applyExemplosExamples
delonix secret apply -f segredos.yamlsecret rm
Remove a secret
Usage: delonix secret rm [OPTIONS] <NAME>
Arguments:
<NAME>
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# remove a secret for good — a container that names it fails loudly on the
# next start
delonix secret rm db-pass
SEE ALSO:
delonix secret ls · delonix secret unset · delonix secret create
delonix › secret › rmExemplosExamples
delonix secret rm db-credssecret unset
Remove a key from a secret (or the whole secret with --all)
Usage: delonix secret unset [OPTIONS] <NAME> [KEY]
Arguments:
<NAME>
[KEY]
Options:
--all
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# drop a single key, keeping the secret and everything else in it
delonix secret unset db-pass PASSWORD
# empty the whole secret in one go
delonix secret unset db-pass --all
SEE ALSO:
delonix secret set · delonix secret rm · delonix secret inspect
delonix › secret › unsetExemplosExamples
delonix secret unset db-creds passwordsecret set
Set/update keys in a secret (creates it if it does not exist)
Usage: delonix secret set [OPTIONS] <NAME> [PAIRS]...
Arguments:
<NAME>
[PAIRS]...
`KEY=value` pairs
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# add or update one key and leave the rest untouched
delonix secret set db-pass PASSWORD=n3w
# several keys at once — creates the secret if it does not exist yet
delonix secret set db-pass USER=app PASSWORD=n3w
SEE ALSO:
delonix secret unset · delonix secret create · delonix secret inspect
delonix › secret › setExemplosExamples
delonix secret set db-creds user=admin password=s3cr3tsecret create
Create a secret from literals and/or a .env file.
Refuses if the name already exists — pass --force to replace it, or use secret set to add/update keys instead.
Usage: delonix secret create [OPTIONS] <NAME>
Arguments:
<NAME>
Options:
--from-literal <FROM_LITERAL>
`KEY=value` pair. Repeatable
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
--from-env-file <FROM_ENV_FILE>
Load `KEY=value` lines from a file (e.g. `.env`), or `-` to read them from stdin (the value never touches argv/process list)
--from-env <FROM_ENV>
Take the value from an environment VARIABLE: `--from-env DB_PASSWORD` stores `$DB_PASSWORD` under that name, `--from-env password=PGPASSWORD` under `password`. Repeatable. The value never appears in argv, unlike `--from-literal`
-f, --force
Replace an EXISTING secret instead of refusing. Without it, `create` only creates — the same guarantee `kubectl create secret`/`docker secret create` give; use `secret set` to add or update keys of one that already exists without this flag
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# from literal pairs — quick, but the value lands in your shell history
delonix secret create db-pass --from-literal PASSWORD=s3cr3t
# from a `.env` file, every key at once
delonix secret create db-pass --from-env-file .env
# from stdin — the dry form: the value touches neither argv nor the history
printf 'PASSWORD=s3cr3t\n' | delonix secret create db-pass --from-env-file -
SEE ALSO:
delonix secret set · delonix secret ls · delonix secret apply · delonix
container run
delonix › secret › createExemplosExamples
printf 'password=s3nha' | delonix secret create db-pass --from-env-file -secret ls
List the secrets (name + number of keys; values NEVER shown)
Usage: delonix secret ls [OPTIONS]
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-o, --output <OUTPUT>
Output format: `table` (default) or `json` (ADR-0005)
[default: table]
[possible values: table, json]
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# the vault at a glance — name and number of keys, never a value
delonix secret ls
# as JSON, for a script
delonix secret ls -o json
SEE ALSO:
delonix secret inspect · delonix secret create · delonix secret rm
delonix › secret › lsExemplosExamples
delonix secret lssecret inspect
Show the keys of a secret (values redacted, unless --reveal)
Usage: delonix secret inspect [OPTIONS] <NAME>
Arguments:
<NAME>
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
--reveal
Reveal the VALUES in cleartext (dangerous — avoid on shared terminals)
-o, --output <OUTPUT>
Output format: `table` (default, the historical text) or `json` (ADR-0005). Redaction applies to BOTH — `--reveal` is what unlocks the values, never the format
[default: table]
[possible values: table, json]
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# which keys a secret carries, with the values redacted
delonix secret inspect db-pass
# the values in cleartext — avoid it on a shared terminal
delonix secret inspect db-pass --reveal
SEE ALSO:
delonix secret ls · delonix secret set · delonix secret unset
delonix › secret › inspectExemplosExamples
delonix secret inspect db-pass --revealsecret rotate-key
Rotate the host master key: re-encrypt ALL secrets with a new key. The values are preserved
Usage: delonix secret rotate-key [OPTIONS]
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# re-encrypt every secret under a new host master key; the values are
# preserved
delonix secret rotate-key
SEE ALSO:
delonix secret ls · delonix secret inspect · delonix secret create
delonix › secret › rotate-keyExemplosExamples
delonix secret rotate-keyLaboratórioLab
Cria um segredo, usa-o num container, e confirma que fica redigido por omissão.
printf 's3nha' | delonix secret create db-pass
delonix container run --rm --secret db-pass alpine env
delonix secret inspect db-pass
delonix secret inspect db-pass --revealCreate a secret, use it in a container, and confirm it's redacted by default.
printf 's3cr3t' | delonix secret create db-pass
delonix container run --rm --secret db-pass alpine env
delonix secret inspect db-pass
delonix secret inspect db-pass --revealDesafioChallenge
Roda a chave do cofre com secret rotate-key e
confirma que o segredo db-pass criado antes continua legível depois — a rotação não
pode obrigar a recriar segredos.
Rotate the vault key with secret rotate-key and confirm
the db-pass secret created earlier is still readable afterwards — rotation must never
force you to recreate secrets.