Skip to content

edgible secret

Manage organization secrets (set/rotate, list, get, delete)

Create or rotate a secret from literals and/or files

Terminal window
edgible secret set <name> [flags]
FlagDescription
--from-literal <key=value>Literal key=value pair (repeatable). Note: visible in shell history and process list — prefer —from-file / —from-env-file for sensitive values
--from-file <key=path>Read a value from a file: key=path (repeatable). The file contents become the value
--from-env-file <path>Read KEY=VALUE lines from a dotenv-style file (repeatable)
--type <type>Secret type: opaque or dockerconfigjson (default: opaque)

Examples

Terminal window
edgible secret set db-password --from-literal password=hunter2
edgible secret set tls-cert --from-file cert=./server.crt --from-file key=./server.key
edgible secret set app-env --from-env-file ./production.env
edgible secret set registry-creds --from-file .dockerconfigjson=./docker-config.json --type dockerconfigjson

Sources are additive and repeatable: combine --from-literal, --from-file and --from-env-file on one call to build up a multi-key secret. Running this again on an existing name ROTATES it — every application referencing it picks up the new value on its next deploy, no application command required. --from-literal is visible in shell history and the process list; prefer --from-file or --from-env-file for anything sensitive.

Aliases: ls

List all secrets in the organization (metadata only)

Terminal window
edgible secret list [flags]

Examples

Terminal window
edgible secret list
edgible secret list --json | jq -r '.[].name'

Lists names and key metadata only — no secret ever prints its value here.

Show a secret’s metadata (key names + checksum, never values)

Terminal window
edgible secret get <name> [flags]

Examples

Terminal window
edgible secret get db-password
edgible secret get tls-cert --json

Prints the key names and the drift checksum only — never the value. The checksum changes on every secret set that rotates it, so comparing it against a value you noted earlier tells you whether the secret has rotated since.

Aliases: rm

Delete a secret (refused while a live application references it)

Terminal window
edgible secret delete <name> [flags]
FlagDescription
-y, --yesSkip the confirmation prompt

Examples

Terminal window
edgible secret delete db-password
edgible secret rm db-password --yes

Refused with the referencing applications listed while any live application still points at this secret — remove the reference from each one first (or secret set a replacement) and delete afterward.