feat: add enable/disable support for user secrets (#27537)

Users can now disable a secret to stop it from being injected into
workspaces without deleting it, and re-enable it later. Disabled secrets
stay visible and editable everywhere they already appear.

An enabled secret must have at least one injection target; a secret with
no target can be stored only while disabled. Existing target-less secrets
are migrated to disabled to preserve current behavior.

Support spans the REST API, SDK, CLI, dashboard, and audit log.
This commit is contained in:
Zach
2026-07-28 09:58:33 -06:00
committed by GitHub
parent 3c61a9a939
commit 85984ff142
56 changed files with 1391 additions and 186 deletions
+10
View File
@@ -19269,6 +19269,9 @@ const docTemplate = `{
"description": {
"type": "string"
},
"enabled": {
"type": "boolean"
},
"env_name": {
"type": "string"
},
@@ -26044,6 +26047,9 @@ const docTemplate = `{
"description": {
"type": "string"
},
"enabled": {
"type": "boolean"
},
"env_name": {
"type": "string"
},
@@ -26652,6 +26658,10 @@ const docTemplate = `{
"description": {
"type": "string"
},
"enabled": {
"description": "Enabled controls whether the secret is injected into workspaces.\nDisabled secrets remain visible and editable, but are not added\nto the agent manifest, so they are not exposed as environment\nvariables or written to secret files.",
"type": "boolean"
},
"env_name": {
"type": "string"
},
+10
View File
@@ -17436,6 +17436,9 @@
"description": {
"type": "string"
},
"enabled": {
"type": "boolean"
},
"env_name": {
"type": "string"
},
@@ -23938,6 +23941,9 @@
"description": {
"type": "string"
},
"enabled": {
"type": "boolean"
},
"env_name": {
"type": "string"
},
@@ -24519,6 +24525,10 @@
"description": {
"type": "string"
},
"enabled": {
"description": "Enabled controls whether the secret is injected into workspaces.\nDisabled secrets remain visible and editable, but are not added\nto the agent manifest, so they are not exposed as environment\nvariables or written to secret files.",
"type": "boolean"
},
"env_name": {
"type": "string"
},