Add optional <version> argument to abra app secret rm to allow deleting a specific secret version
#615
Open
opened 2025-08-25 20:06:58 +00:00 by 3wordchant
·
4 comments
No Branch/Tag Specified
main
renovate/golang-1.27
local-integration-testing
renovate/github.com-charmbracelet-bubbletea-2.x
fix/492
renovate/github.com-charmbracelet-lipgloss-2.x
renovate/otel-weaver-0.x
renovate/codespell-2.x
renovate/tonistiigi-xx-1.x
renovate/alpine-3.x
renovate/github.com-charmbracelet-log-2.x
chore-deps
fix/deps
fix/613
0.13.0-beta
0.13.0-rc2-beta
0.13.0-rc1-beta
0.12.0-beta
0.11.0-beta
0.10.1-beta
0.10.0-beta
0.10.0-rc2-beta
0.10.0-rc1-beta
0.9.0-beta
0.8.1-beta
0.8.0-beta
0.8.0-rc2-beta
0.8.0-rc1-beta
0.7.0-beta
0.7.0-rc3-beta
0.7.0-rc2-beta
0.6.0-beta
0.5.1-beta
0.5.0-alpha
0.4.1-alpha
0.4.0-alpha
0.4.0-alpha-rc8
0.4.0-alpha-rc7
0.4.0-alpha-rc6
0.4.0-alpha-rc5
0.4.0-alpha-rc4
0.4.0-alpha-rc3
0.4.0-alpha-rc2
0.4.0-alpha-rc1
0.3.1-alpha-rc2
0.3.1-alpha-rc1
0.3.1-rc1
0.3.0-alpha
0.2.2-alpha
0.2.1-alpha
0.2.0-alpha
0.1.8-alpha
0.1.7-alpha
0.1.6-alpha
0.1.5-alpha
0.1.4-alpha
0.1.3-alpha
0.1.2-alpha
0.1.1-alpha
0.1.0-alpha
10.0.5
10.0.3
10.0.2
10.0.1
10.0.0
9.0.0
8.0.1
8.0.0
0.7.4
0.7.3
0.7.2
0.7.1
0.7.0
checkout
0.6.0
0.5.0
0.4.1
0.4.0
0.3.1
0.3.0
0.2.0
0.1.2
0.1.1
0.1.0
Labels
Clear labels
bug
build
ci/cd
critical fix
design
documentation
duplicate
easy-first-issue
enhancement
help wanted
i10n
i18n
installer
invalid
question
release
release-candidate
security
tech-debt
test
wontfix
Something is not working
go build related issues
Building things with CI/CD
https://docs.coopcloud.tech/federation/resolutions/passed/010/
UI/UX
Documenting all the things
This issue or pull request already exists
Something for new people to get stuck into. We hope it's easy!
New feature
Need some help
Everything to do with localisation
Everything to do with internationalisation
Everything to do with the install script.
Something is wrong
More information is needed
Release management
Related to the new release candidate
Security related
Unit/integration testing
This won't be fixed
No labels
enhancement
Milestone
No items
No Milestone
Projects
Clear projects
No projects
Assignees
3wordchant
aadil (Aadil Ayub)
abra-bot (Abra Bot)
ammaratef45
amras (Sarma)
Apfelwurm
BornDeleuze
Brooke
carla
cas (Cassowary)
coopcloud
cyrnel
decentral1se (d1)
dede
devydave
fauno (fauno)
iexos
jade (Jade Ambrose)
jjsfunhouse
jmakdah2 (Jackie Makdah)
joe-irving (Joe Irving)
kawaiipunk (KawaiiPunk)
knoflook
kolaente
lambdabundesverband
linnealovespie (April)
moosemower
moritz
notplants
oxaliq (sorrel)
p4u1
pharaohgraphy (Andrew 🐦🔥❤️🔥✴️)
renovate-bot (Comrade Renovate Bot)
ripclap
simon
sixsmith (Sixsmith)
stevensting
trav (Trav Fryer)
val (val (he/him))
yksflip
Clear assignees
No Assignees
decentral1se
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: toolshed/abra#615
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
...because otherwise it tries to delete all versions and the only way to delete a single version is with
docker secret rm@3wordchant digging into this and wanted to pick your brain on this one...
i guess it's a bug that we should really only be deleting the secret that matches the version we put in the
.envforabra app secret rminvocations. You shouldn't have to put a[version]argument to not nuke your entire history of secretsv[n]back to 1? and actually this breaks rollbacks which might look for a specific version of a secret? 🙈 so, let's fix that as the new default of this sub-command?i also noticed
abra app secret lsdoesn't show secrets that don't match what you put in your.env, e.g. if you haveSECRET_FOO_VERSION=v2thenabra app secret ls <domain>will only matchsecret_foo_v2when querying internally. that actually seems now limited in this use-case. should we be making a distinction inabra app secret lson which secret version is used and which is present but unused for a specific app? The only way (AFAICT) to know there are other "old" secrets present is to usedocker secret ls?then you could know what you need to fill in for
abra app secret rm [secret] [version]by runningabra app secret lsfirst? probably we should prompt a warning "are you sure cus it could break rollback" when deleting a specific version (with--no-inputflag available)?Agreed.
Sounds sensible, maybe a separate ticket for this? Seems lower priority than making
abra app secret rmnot delete unexpected things.Ah @decentral1se I was wrong about "tries to delete all versions", it tries to delete the version specified in the
.env.So I think !642 looks good, and this remains a feature request to be able to delete a specific version :)
Nice, thanks! OK I'm gonna then bump this outta the current code crunch into the new version and we can come back to it. Some of these design questions are still hanging in the air (#615 (comment)) and it would be good to take some time to think about it.