Skip to content
SHC Docs

shc vault rotate

rotate the vault master password (re-encrypts every secret)

Change the vault master password. Every secret is decrypted under the current password and re-encrypted under the new one in a single transaction, then this node switches to the new key. Requires an unlocked vault. Prompts for any password not passed via —old-password / —new-password.

WARNING: passwords passed via flags are visible in shell history and the process list, prefer the interactive prompts (omit the flags).

shc vault rotate [flags]
-h, --help help for rotate
-N, --new-password string new vault password (prompts when empty)
-O, --old-password string current vault password (prompts when empty)
--config stringArray extra YAML config file to layer on top of auto-discovered config; repeatable, later files win
-d, --debug enable debug mode (default: $SHC_DEBUG)
-e, --environment string environment name (default: $SHC_ENVIRONMENT)
--exclude string comma-separated dotted paths to drop
--fields string comma-separated columns/keys to show (and their order)
--filter string comma-separated dotted paths to keep (drops everything else)
-o, --output string output format: tty|text|json|yaml (default: $SHC_OUTPUT)
-p, --password string vault password
-s, --stack string stack name (default: $SHC_STACK)
-t, --tenant string tenant name (default: $SHC_TENANT)
-v, --verbose verbose output (default: $SHC_VERBOSE)