ti fs-vault create-secret
Creates a secret from one or more NAME=value or NAME=@file fields.
Syntax
ti fs-vault create-secret
--field <string>
--secret-name <string>
[--dry-run]
[--file-system-id <string>]
[--fs-token <string>]
[--help]
[--version]
Options
--field <string>: Secret field assignmentkey=value,key=@file, orkey=-; repeatable.key=-reads standard input. If more than one field uses-, each receives the same standard input value. [required]--secret-name <string>: Vault secret name. [required]--dry-run: Validate the request without applying changes.--file-system-id <string>: Select the file system. You can also setTI_FS_FILE_SYSTEM_ID.--fs-token <string>: Set the Filesystem token. If omitted, the command uses theTI_FS_TOKENenvironment variable. If neither is provided, the command uses the local token stored for the selected Filesystem.--help: Display help information.--version: Display version information.
For options shared by all commands, see Global options.
Examples
Create a secret from values and a file:
# Keep the password out of the command line by reading it from a local file. ti fs-vault create-secret --file-system-id <file-system-id> --secret-name db-prod --field DB_URL=mysql://example --field PASSWORD=@./password.txtRead a secret field from standard input:
# Supply a sensitive token through a pipe instead of a process argument. printf '%s' "$API_TOKEN" | ti fs-vault create-secret --file-system-id <file-system-id> --secret-name api-dev --field TOKEN=-Preview secret creation:
# Validate field assignments without storing secret material. ti fs-vault create-secret --file-system-id <file-system-id> --secret-name api-dev --field TOKEN=@./token.txt --dry-run