Relationships
#2733 Docs: local_encryption key-source fields are refused over --server
Opened by stack72 · 9/29/2026
Follows swamp-club#2690. After that fix, swamp serve refuses client-supplied local_encryption key-source fields (base_dir, key_file, ssh_key_path, auto_generate) on vault create, vault edit and vault migrate over --server: edits must keep the stored values, and creates, migrates and repairs get the server defaults (auto_generate true, base_dir = the serve repo). content/manual/reference/vaults.md documents these fields in the local_encryption table and shows vault create with an ssh_key_path config next to the --server flag tables. Add a note to the local_encryption config section and to the vault create, edit and migrate reference entries that these fields can only be set by a local (non --server) invocation, and that over --server the server defaults apply.
Closed
No activity in this phase yet.
stack72 commented 9/29/2026, 11:33:43 PM
Docs fix in swamp-club PR 1265 (one PR covering #2626, #2653, #2661, #2679, #2692, #2694, #2701, #2728, #2733, #2740).
stack72 commented 9/29/2026, 11:35:11 PM
Documented in swamp-club PR 1265. vaults.md: a note in the local_encryption Configuration section, plus lines under vault create and vault migrate and in vault edit: over --server, create and migrate use the server's key-source defaults (auto_generate true, base_dir = the serve repo) and refuse any other value for ssh_key_path, auto_generate, key_file or base_dir; edits must keep the stored values; a remote repair stores the defaults. Choosing these fields needs a local invocation on the serve host.
Sign in to post a ripple.