feat: add enable/disable support for user secrets (#27537)

Users can now disable a secret to stop it from being injected into
workspaces without deleting it, and re-enable it later. Disabled secrets
stay visible and editable everywhere they already appear.

An enabled secret must have at least one injection target; a secret with
no target can be stored only while disabled. Existing target-less secrets
are migrated to disabled to preserve current behavior.

Support spans the REST API, SDK, CLI, dashboard, and audit log.
This commit is contained in:
Zach
2026-07-28 09:58:33 -06:00
committed by GitHub
parent 3c61a9a939
commit 85984ff142
56 changed files with 1391 additions and 186 deletions
+6 -4
View File
@@ -30,10 +30,12 @@ USAGE:
$ coder secret delete api-key
SUBCOMMANDS:
create Create a secret
delete Delete a secret
list List secrets, or show one by name
update Update a secret
create Create a secret
delete Delete a secret
disable Disable a secret without removing it
enable Enable a secret so it is injected into workspaces
list List secrets, or show one by name
update Update a secret
———
Run `coder --help` for a list of global options.
+5
View File
@@ -12,6 +12,11 @@ OPTIONS:
--description string
Set the secret description.
--enabled bool (default: true)
Whether the secret is injected into workspaces. An enabled secret must
set --env or --file; pass --enabled=false to store a secret without
injecting it.
--env string
Name of the workspace environment variable that this secret will set.
+9
View File
@@ -0,0 +1,9 @@
coder v0.0.0-devel
USAGE:
coder secret disable <name>
Disable a secret without removing it
———
Run `coder --help` for a list of global options.
+9
View File
@@ -0,0 +1,9 @@
coder v0.0.0-devel
USAGE:
coder secret enable <name>
Enable a secret so it is injected into workspaces
———
Run `coder --help` for a list of global options.
+1 -1
View File
@@ -10,7 +10,7 @@ USAGE:
Secret values are omitted from the output.
OPTIONS:
-c, --column [created|name|updated|env|file|description] (default: name,created,updated,env,file,description)
-c, --column [created|name|updated|env|file|enabled|description] (default: name,created,updated,env,file,enabled,description)
Columns to display in table output.
-o, --output table|json (default: table)
+8 -3
View File
@@ -5,14 +5,19 @@ USAGE:
Update a secret
At least one of --value, --description, --env, or --file must be specified.
Provide the secret value by at most one of --value or non-interactive stdin
(pipe or redirect).
At least one of --value, --description, --env, --file, or --enabled must be
specified. Provide the secret value by at most one of --value or
non-interactive stdin (pipe or redirect).
OPTIONS:
--description string
Update the secret description. Pass an empty string to clear it.
--enabled bool
Whether the secret is injected into workspaces. An enabled secret must
keep at least one of --env or --file; pass --enabled=false to stop
injecting it without deleting it.
--env string
Name of the workspace environment variable that this secret will set.
Pass an empty string to clear it.