feat: add enable/disable support for user secrets (#27537)

Users can now disable a secret to stop it from being injected into
workspaces without deleting it, and re-enable it later. Disabled secrets
stay visible and editable everywhere they already appear.

An enabled secret must have at least one injection target; a secret with
no target can be stored only while disabled. Existing target-less secrets
are migrated to disabled to preserve current behavior.

Support spans the REST API, SDK, CLI, dashboard, and audit log.
This commit is contained in:
Zach
2026-07-28 09:58:33 -06:00
committed by GitHub
parent 3c61a9a939
commit 85984ff142
56 changed files with 1391 additions and 186 deletions
+2
View File
@@ -2098,6 +2098,7 @@ func UserSecret(secret database.ListUserSecretsRow) codersdk.UserSecret {
Description: secret.Description,
EnvName: secret.EnvName,
FilePath: secret.FilePath,
Enabled: secret.Enabled,
CreatedAt: secret.CreatedAt,
UpdatedAt: secret.UpdatedAt,
}
@@ -2112,6 +2113,7 @@ func UserSecretFromFull(secret database.UserSecret) codersdk.UserSecret {
Description: secret.Description,
EnvName: secret.EnvName,
FilePath: secret.FilePath,
Enabled: secret.Enabled,
CreatedAt: secret.CreatedAt,
UpdatedAt: secret.UpdatedAt,
}