Skip to content

feature: rekey a single secret by filename - #424

Open
ryantm wants to merge 1 commit into
refactor/issue401-cli-rulesfrom
feature/issue143-rekey-file
Open

ryantm wants to merge 1 commit into
refactor/issue401-cli-rulesfrom
feature/issue143-rekey-file

Conversation

@ryantm

@ryantm ryantm commented Oct 2, 2026

Copy link
Copy Markdown
Owner

Add agenix --rekey-file FILE to apply the current recipient rule to one existing secret. The command accepts -i and -j, resolves the filename from the rules directory, preserves plaintext, and leaves other ciphertext untouched. It requires decryption access and ignores the editor and piped input.

Unlike rekeying the whole set, this only evaluates the selected rule, so unrelated rules may be unavailable. Missing files and missing identities fail without creating or replacing the target.

Based on #423 and its documented dependencies; none have been merged.

Validation: package CLI/shellcheck, plugin check, and rules tests covering exact one-file selection, one evaluation, unusual filenames, leading ./ and hyphens, ignored piped input/editor, missing identity/file/argument, unrelated failing rules, and preserved excluded ciphertext.

Closes #143.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant