Skip to content
Console
Menu

Queues

Workflows

Getting Started

Authentication

KV Store

sylphx secrets secrets

Every sylphx secrets secrets command: its argument, its flags and a run line.

The secrets commands of Sylphx Secrets, as the CLI spells them: the same calls as the secrets API page, typed for the shell. Install, sign in and the grammar are on the CLI index.

#get

Gets a secret.

NAME — the resource's name; a bare id is enough below the linked project.

CLI

Shell
sylphx secrets secrets get orgs/acme/projects/shop/envs/production/secrets/secret

GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets/secret · scope secrets:read · effect read · Request, response and examples

#list

Lists secrets in an environment.

PARENT — optional: the CLI fills it from the linked project or the key's scope when it is left out.

CLI

Shell
sylphx secrets secrets list orgs/acme/projects/shop/envs/production

GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets · scope secrets:read · effect read · Request, response and examples

Flags

FlagTypeWhat it does
--page-sizeintAt most this many; default 50, clamped to 1000.
--page-tokenstringnext_page_token of the previous page.
--filterstringAIP-160 filter over labels and filterable fields.
--order-bystringAIP-132 ordering over filterable fields.

#create

Creates a secret, without a value; add one with CreateSecretVersion.

ID — The id segment of the new Resource's name; the server assigns one when omitted.

CLI

Shell
sylphx secrets secrets create --parent orgs/acme/projects/shop/envs/production

POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets · scope secrets:write · effect write · Request, response and examples

Flags

FlagTypeWhat it does
--parentstringThe parent to create in; defaults to the linked project or the key's scope.
--meta.labelskey=valueCaller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value.
--meta.annotationskey=valueCaller-writable, unindexed annotations. Repeat the flag for each value.
--meta.display-namestringCaller-writable human-readable name.
--spec.encryption-keystringThe ENCRYPT Key the values are envelope-encrypted with; unset means the environment's default Key.
--spec.rotation-perioddurationHow often the value should be rotated; the Secret reports Ready=FALSE with reason RotationDue once the latest version is older.
--spec.deletion-protectionboolWhile true, Delete fails with DELETION_PROTECTED. Default true.
--dry-runboolValidate and print the result without writing (validate_only).

#update

Updates a secret.

NAME — the resource's name; a bare id is enough below the linked project.

CLI

Shell
sylphx secrets secrets update orgs/acme/projects/shop/envs/production/secrets/secret

PATCH https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets/secret · scope secrets:write · effect write · Request, response and examples

Flags

FlagTypeWhat it does
--meta.labelskey=valueCaller-writable, indexed labels (AIP-122 label rules). Repeat the flag for each value.
--meta.annotationskey=valueCaller-writable, unindexed annotations. Repeat the flag for each value.
--meta.display-namestringCaller-writable human-readable name.
--spec.rotation-perioddurationHow often the value should be rotated; the Secret reports Ready=FALSE with reason RotationDue once the latest version is older.
--spec.deletion-protectionboolWhile true, Delete fails with DELETION_PROTECTED. Default true.
--dry-runboolValidate and print the result without writing (validate_only).

#delete

Deletes a secret and destroys every version.

NAME — the resource's name; a bare id is enough below the linked project.

CLI

Shell
sylphx secrets secrets delete orgs/acme/projects/shop/envs/production/secrets/secret --yes

DELETE https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/secrets/secret · scope secrets:write · effect destructive · Request, response and examples

Flags

FlagTypeWhat it does
--etagstringDelete only if the current etag matches.
--dry-runboolValidate and print the result without writing (validate_only).
--forceboolAlso delete every child Resource; without it a parent with children fails with FAILED_PRECONDITION.
--yesboolDo not ask before this destructive call.