sops_update_external
Update an external secret in a SOPS-encrypted file after rotating an upstream API key. Recomputes derived secrets referencing the changed key and rejects generated or derived entries.
Instructions
Replace the value of an 'external' secret (e.g. after the user rotated an upstream API key). Rejects attempts to update 'generated' or 'derived' secrets — use sops_rotate_generated for those. Recomputes any derived secrets that reference this key. Requires a private key for the domain.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| value | Yes | New plaintext value | |
| domain | No | Name of the key domain to encrypt to / decrypt with. Optional. Defaults to the domain recorded in the file's _meta_unencrypted block, and failing that to 'default'. Call sops_list_domains to see what this server has configured. | |
| key_name | Yes | Key to update | |
| encrypted_content | Yes | Contents of an existing secrets.enc.yaml file |