strazactl apps secret set
Store the server's own secret, or with --role the override one role uses instead
On this page
Synopsis
Stores a static secret the gateway injects into calls to the server and never shows a client. Run in a terminal, the command asks for the value at a hidden prompt. In a script, set STRAZA_SECRET_VALUE from a secret manager instead. --value also works, but it puts the secret in the process arguments and the shell history.
The answer prints the secret’s fingerprint, never its value, and setting it again replaces the stored value. A server whose manifest leaves no use for a static secret, such as one that declares no credential, refuses it and names the manifest change.
strazactl apps secret set <server> [flags]
Examples
strazactl apps secret set scout-tools
strazactl apps secret set scout-tools --role scout-role
Options
--role string store the override for this role instead of the server's own secret
--value string secret value; it shows in process arguments and shell history, so leave it out and type the value at the hidden prompt
Options inherited from parent commands
--server string strazad base URL (overrides $STRAZA_SERVER and the server you logged into)
See also
- strazactl apps secret: Manage a server’s static secret (injected gateway-side, never client-visible)