Peren documentation
Rotate secrets
Write declared secrets into the local store as metadata-only generations.
Update a declared Worker secret in the local secrets store without printing the secret value. The store lives under PEREN_DATA_DIR/secrets. A running process loads secret values at start; it does not reread the store for later rotations.
Prerequisites
- The secret name is declared in the fleet config (
secrets_store, servicesecrets, orsecrets_store_refs). [secrets].providerislocal. Other providers refuse the secrets CLI with an unimplemented-provider error.
Put or rotate
peren secrets put and peren secrets rotate both write a new active generation for the named secret.
peren secrets rotate peren.toml --name STRIPE_SECRET_KEY --value "$STRIPE_SECRET_KEY"
Representative output is metadata only:
STRIPE_SECRET_KEY version=2 digest=<sha256> created_at_ms=<timestamp>
Empty values are refused.
List, get, and delete
peren secrets list peren.toml
peren secrets get peren.toml --name STRIPE_SECRET_KEY
List and get print the same metadata fields. They do not print the secret value.
peren secrets delete peren.toml --name STRIPE_SECRET_KEY
Failure cases
| Symptom | Cause | Next action |
|---|---|---|
| Secret is not declared by the fleet config | Name missing from config declarations | Add the declaration, then retry |
| Secrets provider is not implemented | Non-local [secrets].provider |
Use local, or supply values through the declared environment path |
| No active local value | Get against a name with no stored generation | Put or rotate first |
Related: Secrets binding, Operations overview, Security.