Secrets Rotation
Secrets Rotation
Overview
Secrets and configs are content-addressed as <name>.<hash8>. New content creates a new object, and the CLI patches the Compose reference for every service attached with --for. The previous object stays in Swarm until you remove it.
Rotate a Value
- Run the create command again with the new value:
echo "${NEW_POSTGRES_PASSWORD}" | minipaas deploy secret dev \
--name postgres_password \
--for postgres --for api- The CLI computes a new name and patches the last Compose file that defines each service.
- Roll out the stack so services pick up the new reference:
minipaas deploy rollout dev- Remove the previous object once the rollout succeeds:
docker secret ls
docker secret rm postgres_password.<old-hash>Notes
- The mounted file name inside containers stays
<name>, so applications do not change. deploy configfollows the same model for non-sensitive files.- Only services listed with
--forare patched; update any other consumers explicitly. - Running the command again with the same content reuses the existing object.
See Secrets & Configs for naming and CLI details.