sops_add_metadata
Adds missing _meta_unencrypted metadata to an existing SOPS-encrypted file by decrypting, adding metadata, and re-encrypting while preserving plaintext values.
Instructions
Add _meta_unencrypted metadata to an existing SOPS-encrypted file that lacks it. Decrypts the file, adds metadata, and re-encrypts preserving original plaintext values. Requires a private key for the target domain.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| domain | No | Name of the key domain to encrypt to / decrypt with. Optional. Defaults to the domain recorded in the file's _meta_unencrypted block, and failing that to 'default'. Call sops_list_domains to see what this server has configured. | |
| secret_metadata | Yes | Mapping of key names to metadata. Each value has 'source' ('generated', 'external', or 'derived') and optional 'description'. For 'derived', also provide 'transform' and 'from'. | |
| encrypted_content | Yes | Contents of a secrets.enc.yaml file |