Skip to content

Secrets store: sensitive:false plaintext rows (readable non-secret config values) #1588

Description

@kriszyp

Follow-up to #715 / PR #1554 (store) and #1550 / PR #1582 (consumption), from the P1b design decision.

Problem

The hdb_secret store treats every row as sensitive: values are write-only through the operations API (never returned by reads), redacted in MCP audit surfaces, and read_audit_log is blocked for the table. That is the right default, but some configuration values are shared, non-secret settings (feature flags, service URLs, tuning values) that teams still want centrally stored, replicated, and delivered through the same env: declaration surface — without losing the ability to read them back in Studio/ops tooling.

Today the only options for non-secret values are inline literals in each component's env: block (not centrally managed) or storing them as secrets (write-only, so ops can't view/diff them).

Proposal

Add a sensitive: false flag on hdb_secret rows (default true, preserving current behavior):

  • sensitive: false rows store the value as plaintext (no enc: envelope required) and are readable back through the operations API (get_secret/list_secrets return the value) and Studio.
  • Redaction, audit-read blocking, and MCP default-deny continue to apply only to sensitive: true rows — audit redaction becomes conditional on the flag.
  • Consumption side (Two-tier component secret delivery + env declarations (#1550) #1582's env: declarations, grants/two-tier delivery) is unchanged: a declaration resolves the row the same way regardless of sensitivity.
  • Flag flips: false → true is allowed (tightening). true → false must be rejected — the stored value was written under write-only expectations and must not become readable after the fact; require a new value write to downgrade.

Acceptance

  • Row schema + operations validation accept sensitive: false; default remains true.
  • Non-sensitive rows readable via ops API; sensitive rows remain write-only (existing tests unchanged).
  • true → false transition rejected without a new value.
  • Audit/MCP redaction conditional on the flag, with tests for both settings.

Activity

  1. dawsontoth commented on Jul 3, 2026

    @dawsontoth
    Contributor

    Sounds good to me

  2. added this to the v5.3 milestone on Aug 7, 2026
  3. added theissue type on Aug 7, 2026
  4. modified the milestones: v5.3, v5.4 on Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:componentsComponents / applications subsystemenhancementNew feature or request

Fields

Priority

P2

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions