Skip to content
Console
Menu

Getting Started

Authentication

KV Store

sylphx secrets profiles

Every sylphx secrets profiles command: its argument, its flags and a run line.

The profiles commands of Sylphx Secrets, as the CLI spells them: the same calls as the profiles API page, typed for the shell. Install, sign in and the grammar are on the CLI index.

#get

Gets a profile: its kind, grants, sites and latest version; never a value.

NAME — the resource's name; a bare id is enough below the linked project.

CLI

Shell
sylphx secrets profiles get orgs/acme/projects/shop/envs/production/profiles/profile

GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile · scope secrets:read · effect read · Request, response and examples

#list

Lists the profiles of an environment.

PARENT — optional: the CLI fills it from the linked project or the key's scope when it is left out.

CLI

Shell
sylphx secrets profiles list orgs/acme/projects/shop/envs/production

GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles · scope secrets:read · effect read · Request, response and examples

Flags

FlagTypeWhat it does
--page-sizeintAt most this many; default 50, clamped to 1000.
--page-tokenstringnext_page_token of the previous page.
--filterstringAIP-160 filter over labels and filterable fields.
--order-bystringAIP-132 ordering over filterable fields.

#create

Creates an empty profile; its first version is written by a write-back mount (:open with WRITE_BACK, then :commit).

ID — The id segment of the new Resource's name; the server assigns one when omitted.

CLI

Shell
sylphx secrets profiles create --parent orgs/acme/projects/shop/envs/production --spec.kind browser

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles · scope secrets:write · effect write · Request, response and examples

Flags

FlagTypeWhat it does
--parentstringThe parent to create in; defaults to the linked project or the key's scope.
--meta.labelskey=valueCaller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value.
--meta.annotationskey=valueCaller-writable, unindexed annotations. Repeat the flag for each value.
--meta.display-namestringCaller-writable human-readable name.
--spec.kindenumWhat the profile holds. Required. One of browser, computer.
--spec.grantsjsonWho may mount it and how. A principal with no grant cannot mount it, whatever its scopes. Repeat the flag for each value.
--spec.pathsstringFor a computer profile: the paths under the sandbox's home directory its archive holds, for example .config/app. Repeat the flag for each value.
--dry-runboolValidate and print the result without writing (validate_only).

#update

Updates a profile's grants or declared paths. Granting a mount is this call: nothing else adds a grant.

NAME — the resource's name; a bare id is enough below the linked project.

CLI

Shell
sylphx secrets profiles update orgs/acme/projects/shop/envs/production/profiles/profile

PATCH https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile · scope secrets:write · effect write · Request, response and examples

Flags

FlagTypeWhat it does
--meta.labelskey=valueCaller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value.
--meta.annotationskey=valueCaller-writable, unindexed annotations. Repeat the flag for each value.
--meta.display-namestringCaller-writable human-readable name.
--spec.grantsjsonWho may mount it and how. A principal with no grant cannot mount it, whatever its scopes. Repeat the flag for each value.
--spec.pathsstringFor a computer profile: the paths under the sandbox's home directory its archive holds, for example .config/app. Repeat the flag for each value.
--dry-runboolValidate and print the result without writing (validate_only).

#delete

Deletes a profile; with force, a profile that has versions too, which destroys every version.

NAME — the resource's name; a bare id is enough below the linked project.

CLI

Shell
sylphx secrets profiles delete orgs/acme/projects/shop/envs/production/profiles/profile --yes

DELETE https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile · scope secrets:write · effect destructive · Request, response and examples

Flags

FlagTypeWhat it does
--etagstringDelete only if the current etag matches.
--dry-runboolValidate and print the result without writing (validate_only).
--forceboolAlso destroy every version; without it a profile with versions fails with INVALID_STATE.
--yesboolDo not ask before this destructive call.

#open

Mounts a profile for one session: returns the state of one version and, for WRITE_BACK, an attachment that :commit writes through until it expires. Every call is audited with the caller's context; the caller's principal needs a grant of at least the requested mode.

NAME — the resource's name; a bare id is enough below the linked project.

CLI

Shell
sylphx secrets profiles open orgs/acme/projects/shop/envs/production/profiles/profile

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile:open · scope secrets:mount · effect read · Request, response and examples

Flags

FlagTypeWhat it does
--modeenumREAD_ONLY (the default) or WRITE_BACK. One of read_only, write_back.
--versionstringA version to mount; unset mounts the latest.
--ttldurationHow long a WRITE_BACK attachment may commit; default 1 hour, at most 12 hours. A lost session cannot write back after it.
--contextkey=valueWho mounts it, for the audit trail: for example run, step, member. At most 16 entries; keys and values are names, never values. Repeat the flag for each value.

#commit

Writes a mounted profile back as a new version, by compare-and-set on the version the attachment was opened at (or last committed). When another write landed first, nothing is lost: the result is still a new version, merged site by site with the newer write winning, and marked as a conflict.

NAME — the resource's name; a bare id is enough below the linked project.

CLI

Shell
sylphx secrets profiles commit orgs/acme/projects/shop/envs/production/profiles/profile

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/profiles/profile:commit · scope secrets:mount · effect write · Request, response and examples

Flags

FlagTypeWhat it does
--attachmentstringThe attachment OpenProfile returned with WRITE_BACK. Required.
--statestringThe whole state to write, in the profile kind's form, at most 2 MiB. Required. The value is never returned.