KoshKOSH

kosh rotate

Rotate a secret, generate a new value and a new encrypted reference.

Overview

kosh rotate replaces a secret with a new value and issues a new vault reference. This is useful when a credential has been compromised or you want to enforce regular rotation.

Usage

kosh rotate --key <NAME>

Flags

FlagShortDescription
--key <NAME>-kName of the secret to rotate

Example

$ kosh rotate --key STRIPE_KEY
New value: [hidden]
✓ Rotated STRIPE_KEY
  Old ref: kosh:ref:v1:c3RyaXBla2V5
  New ref: kosh:ref:v1:bmV3cmVma2V5

Difference from kosh edit

kosh editkosh rotate
Updates value✓✓
Issues new reference✗✓
Old ref still valid✓✗ (invalidated)

Notes

  • After rotation, the old reference is invalidated and cannot be decrypted.
  • Push changes to the server with kosh sync --push so teammates get the new reference.

On this page