Files
coder/docs/reference/cli/secret_update.md
T
Zach 85984ff142 feat: add enable/disable support for user secrets (#27537)
Users can now disable a secret to stop it from being injected into
workspaces without deleting it, and re-enable it later. Disabled secrets
stay visible and editable everywhere they already appear.

An enabled secret must have at least one injection target; a secret with
no target can be stored only while disabled. Existing target-less secrets
are migrated to disabled to preserve current behavior.

Support spans the REST API, SDK, CLI, dashboard, and audit log.
2026-07-28 09:58:33 -06:00

59 lines
1.4 KiB
Markdown
Generated

<!-- DO NOT EDIT | GENERATED CONTENT -->
# secret update
Update a secret
## Usage
```console
coder secret update [flags] <name>
```
## Description
```console
At least one of --value, --description, --env, --file, or --enabled must be specified. Provide the secret value by at most one of --value or non-interactive stdin (pipe or redirect).
```
## Options
### --value
| | |
|------|---------------------|
| Type | <code>string</code> |
Update the secret value. For security reasons, prefer non-interactive stdin (pipe or redirect).
### --description
| | |
|------|---------------------|
| Type | <code>string</code> |
Update the secret description. Pass an empty string to clear it.
### --env
| | |
|------|---------------------|
| Type | <code>string</code> |
Name of the workspace environment variable that this secret will set. Pass an empty string to clear it.
### --file
| | |
|------|---------------------|
| Type | <code>string</code> |
Workspace file path where this secret will be written. Must start with ~/ or /. Pass an empty string to clear it.
### --enabled
| | |
|------|-------------------|
| Type | <code>bool</code> |
Whether the secret is injected into workspaces. An enabled secret must keep at least one of --env or --file; pass --enabled=false to stop injecting it without deleting it.