Menu
Platform
AI
App store purchases
Database
Flags
Jobs and cron
Localization
Monitoring
Notifications
Payments
Queues
Sandboxes
Webhooks
Getting Started
Authentication
KV Store
Deploy & Infrastructure
Reference
sylphx secrets secrets
Every sylphx secrets secrets command: its argument, its flags and a run line.
The secrets commands of Sylphx Secrets, as the CLI spells them: the same
calls as the secrets API page, typed for the
shell. Install, sign in and the grammar are on the CLI index.
#get
Gets a secret.
NAME — the resource's name; a bare id is enough below the linked
project.
CLI
sylphx secrets secrets get orgs/acme/projects/shop/envs/production/secrets/secretGET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets/secret · scope secrets:read · effect read · Request, response and examples
#list
Lists secrets in an environment.
PARENT — optional: the CLI fills it from the linked project or the
key's scope when it is left out.
CLI
sylphx secrets secrets list orgs/acme/projects/shop/envs/productionGET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets · scope secrets:read · effect read · Request, response and examples
Flags
| Flag | Type | What it does |
|---|---|---|
--page-size | int | At most this many; default 50, clamped to 1000. |
--page-token | string | next_page_token of the previous page. |
--filter | string | AIP-160 filter over labels and filterable fields. |
--order-by | string | AIP-132 ordering over filterable fields. |
#create
Creates a secret, without a value; add one with CreateSecretVersion.
ID — The id segment of the new Resource's name; the server assigns one when omitted.
CLI
sylphx secrets secrets create --parent orgs/acme/projects/shop/envs/productionPOST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets · scope secrets:write · effect write · Request, response and examples
Flags
| Flag | Type | What it does |
|---|---|---|
--parent | string | The parent to create in; defaults to the linked project or the key's scope. |
--meta.labels | key=value | Caller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value. |
--meta.annotations | key=value | Caller-writable, unindexed annotations. Repeat the flag for each value. |
--meta.display-name | string | Caller-writable human-readable name. |
--spec.encryption-key | string | The ENCRYPT Key the values are envelope-encrypted with; unset means the environment's default Key. |
--spec.rotation-period | duration | How often the value should be rotated; the Secret reports Ready=FALSE with reason RotationDue once the latest version is older. |
--spec.deletion-protection | bool | While true, Delete fails with DELETION_PROTECTED. Default true. |
--dry-run | bool | Validate and print the result without writing (validate_only). |
#update
Updates a secret.
NAME — the resource's name; a bare id is enough below the linked
project.
CLI
sylphx secrets secrets update orgs/acme/projects/shop/envs/production/secrets/secretPATCH https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets/secret · scope secrets:write · effect write · Request, response and examples
Flags
| Flag | Type | What it does |
|---|---|---|
--meta.labels | key=value | Caller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value. |
--meta.annotations | key=value | Caller-writable, unindexed annotations. Repeat the flag for each value. |
--meta.display-name | string | Caller-writable human-readable name. |
--spec.rotation-period | duration | How often the value should be rotated; the Secret reports Ready=FALSE with reason RotationDue once the latest version is older. |
--spec.deletion-protection | bool | While true, Delete fails with DELETION_PROTECTED. Default true. |
--dry-run | bool | Validate and print the result without writing (validate_only). |
#delete
Deletes a secret and destroys every version.
NAME — the resource's name; a bare id is enough below the linked
project.
CLI
sylphx secrets secrets delete orgs/acme/projects/shop/envs/production/secrets/secret --yesDELETE https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets/secret · scope secrets:write · effect destructive · Request, response and examples
Flags
| Flag | Type | What it does |
|---|---|---|
--etag | string | Delete only if the current etag matches. |
--dry-run | bool | Validate and print the result without writing (validate_only). |
--force | bool | Also delete every child Resource; without it a parent with children fails with FAILED_PRECONDITION. |
--yes | bool | Do not ask before this destructive call. |