sops_delete_secrets
Deletes specified keys from an existing SOPS-encrypted file, removing encrypted values and _meta_unencrypted entries while rejecting deletion of keys required by other secrets.
Instructions
Delete one or more keys from an existing SOPS-encrypted file. Removes both the encrypted value and the _meta_unencrypted entry. Rejects deletion of keys that other derived secrets depend on unless those dependents are also in the delete list. Requires a private key for the domain.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| domain | No | Name of the key domain to encrypt to / decrypt with. Optional. Defaults to the domain recorded in the file's _meta_unencrypted block, and failing that to 'default'. Call sops_list_domains to see what this server has configured. | |
| key_names | Yes | Keys to delete | |
| encrypted_content | Yes | Contents of an existing secrets.enc.yaml file |