Browse documentation
On this page

Peren documentation

Rotate secrets

Write declared secrets into the local store as metadata-only generations.

Update a declared Worker secret in the local secrets store without printing the secret value. The store lives under PEREN_DATA_DIR/secrets. A running process loads secret values at start; it does not reread the store for later rotations.

Prerequisites

  • The secret name is declared in the fleet config (secrets_store, service secrets, or secrets_store_refs).
  • [secrets].provider is local. Other providers refuse the secrets CLI with an unimplemented-provider error.

Put or rotate

peren secrets put and peren secrets rotate both write a new active generation for the named secret.

peren secrets rotate peren.toml --name STRIPE_SECRET_KEY --value "$STRIPE_SECRET_KEY"

Representative output is metadata only:

STRIPE_SECRET_KEY version=2 digest=<sha256> created_at_ms=<timestamp>

Empty values are refused.

List, get, and delete

peren secrets list peren.toml
peren secrets get peren.toml --name STRIPE_SECRET_KEY

List and get print the same metadata fields. They do not print the secret value.

peren secrets delete peren.toml --name STRIPE_SECRET_KEY

Failure cases

Symptom Cause Next action
Secret is not declared by the fleet config Name missing from config declarations Add the declaration, then retry
Secrets provider is not implemented Non-local [secrets].provider Use local, or supply values through the declared environment path
No active local value Get against a name with no stored generation Put or rotate first

Related: Secrets binding, Operations overview, Security.