sops_add_secrets
Add new secrets to an existing SOPS-encrypted file by decrypting, merging, and re-encrypting while preserving existing values and rejecting duplicate keys.
Instructions
Add new secrets to an existing SOPS-encrypted file. Decrypts the file, merges in new secrets, and re-encrypts — preserving all existing values and metadata. Rejects keys that already exist in the file. Supports generated, external, and derived sources. Requires a private key for the target domain.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| domain | No | Name of the key domain to encrypt to / decrypt with. Optional. Defaults to the domain recorded in the file's _meta_unencrypted block, and failing that to 'default'. Call sops_list_domains to see what this server has configured. | |
| secrets | Yes | New secrets to add | |
| encrypted_content | Yes | Contents of an existing secrets.enc.yaml file |