Skip to content
Secrets Rotation

Secrets Rotation

Overview

Secrets and configs are content-addressed as <name>.<hash8>. New content creates a new object, and the CLI patches the Compose reference for every service attached with --for. The previous object stays in Swarm until you remove it.


Rotate a Value

  1. Run the create command again with the new value:
echo "${NEW_POSTGRES_PASSWORD}" | minipaas deploy secret dev \
  --name postgres_password \
  --for postgres --for api
  1. The CLI computes a new name and patches the last Compose file that defines each service.
  2. Roll out the stack so services pick up the new reference:
minipaas deploy rollout dev
  1. Remove the previous object once the rollout succeeds:
docker secret ls
docker secret rm postgres_password.<old-hash>

Notes

  • The mounted file name inside containers stays <name>, so applications do not change.
  • deploy config follows the same model for non-sensitive files.
  • Only services listed with --for are patched; update any other consumers explicitly.
  • Running the command again with the same content reuses the existing object.

See Secrets & Configs for naming and CLI details.