Skip to main content
← Back to list
01Issue
BugShippedSwamp CLIPublic
Assigneesstack72

Relationships

#2737 vault create/migrate --config help says local_encryption 'always uses' the server key source

Opened by stack72 · 9/29/2026· Shipped 9/29/2026

Follows swamp-club#2690 (PR #2719). The --config help text on vault create and vault migrate says that with --server a local_encryption vault always uses the server's key source. That reads as if user-supplied values are silently overridden. In fact serve refuses any non-default key-source field (base_dir, key_file, ssh_key_path, auto_generate) and only applies the defaults when those fields are left out. Suggested wording: with --server, local_encryption key-source fields such as key_file and base_dir cannot be set; the server's defaults are used. Consider moving the caveat into the migrate command's long description to keep the option line short, and adding a matching note for vault edit.

02Bog Flow
✓OPEN✓TRIAGED✓IN PROGRESS✓SHIPPED+ 1 MOREASSIGNED+ 6 MOREREVIEW+ 7 MOREPR_MERGED+ 2 MORESESSION_SUMMARIZED

Shipped

9/29/2026, 9:44:07 PM

Click a lifecycle step above to view its details.

03Sludge Pulse
stack72 assigned stack729/29/2026, 9:25:21 PM

Sign in to post a ripple.