delonix secret

Cofre de segredos cifrado em repouso — o produtor do `run --secret`.

Encrypted-at-rest secret vault — the source behind `run --secret`.

Um cofre local (SecretStore) cifrado com XChaCha20-Poly1305. Os valores NUNCA são impressos por omissão (redigidos; --reveal é opt-in). É a fonte dos container run --secret/--secret-files e do --password-secret do volume create — o segredo entra uma vez, nunca fica no histórico do shell nem no manifesto.

A local vault (SecretStore) encrypted with XChaCha20-Poly1305. Values are NEVER printed by default (redacted; --reveal is opt-in). It's the source for container run --secret/--secret-files and volume create's --password-secret — the secret goes in once, and never ends up in shell history or in the manifest.

Usage: delonix secret [OPTIONS] <COMMAND>

Commands:
  create      Create a secret from literals and/or a `.env` file
  rm          Remove a secret
  inspect     Show the keys of a secret (values redacted, unless `--reveal`)
  ls          List the secrets (name + number of keys; values NEVER shown)
  set         Set/update keys in a secret (creates it if it does not exist)
  unset       Remove a key from a secret (or the whole secret with `--all`)
  apply       Apply the `kind: Secret` documents from a manifest
  rotate      Rotate one key's VALUE to a fresh random one
  rotate-key  Rotate the host master key: re-encrypt ALL secrets with a new key. The values are preserved
  help        Print this message or the help of the given subcommand(s)

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

COMMAND MAP:
  Lifecycle    create · rm
  Inspect      ls · inspect
  Configure    set · unset
  Declarative  apply
  Maintenance  rotate · rotate-key

EXAMPLES:
  # what exists — names and key counts; the values are never printed
  delonix secret ls

  # create one without the value ever reaching argv or the shell history
  printf 'PASSWORD=s3cr3t\n' | delonix secret create db-pass --from-env-file -

  # hand it to a container, decrypted only at spawn — the registry keeps the
  # name, never the value
  delonix container run -d --secret db-pass postgres:16

SEE ALSO:
  delonix secret create · delonix secret ls · delonix container run · delonix
  stack apply

  delonix › secret

secret apply

Apply the kind: Secret documents from a manifest.

Declarative — creates the secret without needing secret create on the CLI.

Usage: delonix secret apply [OPTIONS]

Options:
  -f, --file <FILE>
          

      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # create the `kind: Secret` documents of the manifest in this directory
  delonix secret apply

  # from a file of your own, so the vault is provisioned from git like
  # everything else
  delonix secret apply -f examples/secret.yaml

SEE ALSO:
  delonix secret create · delonix stack apply · delonix manifest schema

  delonix › secret › apply

ExemplosExamples

Criar segredos a partir de um manifesto kind: Secret
Create secrets from a kind: Secret manifest
delonix secret apply -f segredos.yaml

secret rm

Remove a secret

Usage: delonix secret rm [OPTIONS] <NAME>

Arguments:
  <NAME>
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # remove a secret for good — a container that names it fails loudly on the
  # next start
  delonix secret rm db-pass

SEE ALSO:
  delonix secret ls · delonix secret unset · delonix secret create

  delonix › secret › rm

ExemplosExamples

Apagar o segredo inteiro
Delete the whole secret
delonix secret rm db-creds

secret unset

Remove a key from a secret (or the whole secret with --all)

Usage: delonix secret unset [OPTIONS] <NAME> [KEY]

Arguments:
  <NAME>
          

  [KEY]
          

Options:
      --all
          

      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # drop a single key, keeping the secret and everything else in it
  delonix secret unset db-pass PASSWORD

  # empty the whole secret in one go
  delonix secret unset db-pass --all

SEE ALSO:
  delonix secret set · delonix secret rm · delonix secret inspect

  delonix › secret › unset

ExemplosExamples

Remover UMA chave (sem apagar o segredo)
Remove ONE key (without deleting the secret)
delonix secret unset db-creds password

secret set

Set/update keys in a secret (creates it if it does not exist)

Usage: delonix secret set [OPTIONS] <NAME> [PAIRS]...

Arguments:
  <NAME>
          

  [PAIRS]...
          `KEY=value` pairs

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # add or update one key and leave the rest untouched
  delonix secret set db-pass PASSWORD=n3w

  # several keys at once — creates the secret if it does not exist yet
  delonix secret set db-pass USER=app PASSWORD=n3w

SEE ALSO:
  delonix secret unset · delonix secret create · delonix secret inspect

  delonix › secret › set

ExemplosExamples

Acrescentar/actualizar chaves de um segredo existente
Add/update keys on an existing secret
delonix secret set db-creds user=admin password=s3cr3t

secret create

Create a secret from literals and/or a .env file.

Refuses if the name already exists — pass --force to replace it, or use secret set to add/update keys instead.

Usage: delonix secret create [OPTIONS] <NAME>

Arguments:
  <NAME>
          

Options:
      --from-literal <FROM_LITERAL>
          `KEY=value` pair. Repeatable

      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

      --from-env-file <FROM_ENV_FILE>
          Load `KEY=value` lines from a file (e.g. `.env`), or `-` to read them from stdin (the value never touches argv/process list)

      --from-env <FROM_ENV>
          Take the value from an environment VARIABLE: `--from-env DB_PASSWORD` stores `$DB_PASSWORD` under that name, `--from-env password=PGPASSWORD` under `password`. Repeatable. The value never appears in argv, unlike `--from-literal`

  -f, --force
          Replace an EXISTING secret instead of refusing. Without it, `create` only creates — the same guarantee `kubectl create secret`/`docker secret create` give; use `secret set` to add or update keys of one that already exists without this flag

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # from literal pairs — quick, but the value lands in your shell history
  delonix secret create db-pass --from-literal PASSWORD=s3cr3t

  # from a `.env` file, every key at once
  delonix secret create db-pass --from-env-file .env

  # from stdin — the dry form: the value touches neither argv nor the history
  printf 'PASSWORD=s3cr3t\n' | delonix secret create db-pass --from-env-file -

SEE ALSO:
  delonix secret set · delonix secret ls · delonix secret apply · delonix
  container run

  delonix › secret › create

ExemplosExamples

Criar um segredo (valor via stdin, não no argv)
Create a secret (value via stdin, not in argv)
printf 'password=s3nha' | delonix secret create db-pass --from-env-file -

secret ls

List the secrets (name + number of keys; values NEVER shown)

Usage: delonix secret ls [OPTIONS]

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -o, --output <OUTPUT>
          Output format: `table` (default) or `json` (ADR-0005)
          
          [default: table]
          [possible values: table, json]

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # the vault at a glance — name and number of keys, never a value
  delonix secret ls

  # as JSON, for a script
  delonix secret ls -o json

SEE ALSO:
  delonix secret inspect · delonix secret create · delonix secret rm

  delonix › secret › ls

ExemplosExamples

Listar (valores redigidos)
List (values redacted)
delonix secret ls

secret inspect

Show the keys of a secret (values redacted, unless --reveal)

Usage: delonix secret inspect [OPTIONS] <NAME>

Arguments:
  <NAME>
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

      --reveal
          Reveal the VALUES in cleartext (dangerous — avoid on shared terminals)

  -o, --output <OUTPUT>
          Output format: `table` (default, the historical text) or `json` (ADR-0005). Redaction applies to BOTH — `--reveal` is what unlocks the values, never the format
          
          [default: table]
          [possible values: table, json]

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # which keys a secret carries, with the values redacted
  delonix secret inspect db-pass

  # the values in cleartext — avoid it on a shared terminal
  delonix secret inspect db-pass --reveal

SEE ALSO:
  delonix secret ls · delonix secret set · delonix secret unset

  delonix › secret › inspect

ExemplosExamples

Revelar explicitamente
Reveal explicitly
delonix secret inspect db-pass --reveal

secret rotate-key

Rotate the host master key: re-encrypt ALL secrets with a new key. The values are preserved

Usage: delonix secret rotate-key [OPTIONS]

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # re-encrypt every secret under a new host master key; the values are
  # preserved
  delonix secret rotate-key

SEE ALSO:
  delonix secret ls · delonix secret inspect · delonix secret create

  delonix › secret › rotate-key

ExemplosExamples

Rodar a chave-mestra (re-cifra tudo)
Rotate the master key (re-encrypts everything)
delonix secret rotate-key

LaboratórioLab

Cria um segredo, usa-o num container, e confirma que fica redigido por omissão.

printf 's3nha' | delonix secret create db-pass
delonix container run --rm --secret db-pass alpine env
delonix secret inspect db-pass
delonix secret inspect db-pass --reveal

Create a secret, use it in a container, and confirm it's redacted by default.

printf 's3cr3t' | delonix secret create db-pass
delonix container run --rm --secret db-pass alpine env
delonix secret inspect db-pass
delonix secret inspect db-pass --reveal

DesafioChallenge

Roda a chave do cofre com secret rotate-key e confirma que o segredo db-pass criado antes continua legível depois — a rotação não pode obrigar a recriar segredos.

Rotate the vault key with secret rotate-key and confirm the db-pass secret created earlier is still readable afterwards — rotation must never force you to recreate secrets.