Documentation
¶
Overview ¶
scripts/secrets is a slim operator tool invoked internally by MemQL's dev-refresh flow. Its only job is to read a .env file and seed manifest-listed entries into a running MemQL as concept rows.
THE `decrypt` SUBCOMMAND IS GONE (epic memql#3958). It opened a genesis.znas envelope into a temp .env, and there is no envelope any more: config has one delivery path, the k8s Secret every node envFroms. secret.OpenBlob lost its last caller with it.
Subcommands:
seed --env-file <path>
Read the .env file, walk MemQL's manifest at
scripts/secrets/manifest.yaml, and upsert manifest-listed
entries into the running MemQL as v1:platform:global*
rows. Entries in the .env that are NOT in the manifest
are ignored -- they're bootstrap-only env vars consumed
from k8s Secrets, not concept rows.
health Quick gRPC handshake check against the running MemQL.
All authoring previously done by `secrets init / set / delete / edit / export / variable-set / variable-delete / list / master-key` has been retired.
Required env:
- MEMQL_MASTER_KEY for seed (it DECRYPTS values at rest; it authenticates nothing -- memql#3519)
- MEMQL_GRPC_ENDPOINT default https://bff.${MEMQL_IDENTITY_BOOTSTRAP_DOMAIN:-memql.localhost}:443
Click to show internal directories.
Click to hide internal directories.