Repository navigation
0.27.0-alpha
Pre-release
Pre-release
·
7 commits
to main
since this release
Changed
- Each secret gets its own tree in the resolution report, after the resource's chain and read
the same way: its state (resolved/MISSING/unknown),used in:(each file of the chain
that writes its placeholder), then every layer and finally the environment variable, each
patched in: <file>ornot patched in. The old one line per secret showed only the winning
file, so an override was invisible. A locked git-crypt file shows at its own layer
(unknown: <file> is locked), and the environment-variable step is shown even when unset, so a
misspelled CI variable is visible — one set but empty says it counts as unset. Names, files and
variable names only, never a value. From a real user's review of the pilot's output; see
docs/SECRETS_DESIGN.md's "What each mode does" and decisions #24–#27. --listends with the same tree, once per secret any of the layer's resources uses, found by
scanning their base files and patches. Replaced resources and resources no engine handles are
left out (neither is ever substituted).- The chain's first step is labelled
resource, notbase, in both the report and--list.
Fixed
--list's header listed every secrets file in the chain under the target layer, as if the
target declared them. It now lists only the target layer's ownsecrets; the rest appear in
the secrets tree, at the layer that lists them.--list --reveal-secretswas silently accepted and did nothing; it's now an error with a
Try:hint, since--listnever shows a value.