Skip to main content

secret, ns

secret

graphenectl secret set <name> [--value <v> | --value-file <path>]
graphenectl secret list
graphenectl secret delete <name>

Secrets live encrypted on the server; only names ever travel — in specs, logs, history, and in this CLI's output. A worker resolves the value at the point of use.

FlagWhat it does
--valuethe value inline
--value-filethe value from a file — raw bytes, never converted
(neither)read the value from stdin
$ graphenectl secret set gh-token --value-file token.txt
secret gh-token set
$ pass show github | graphenectl secret set gh-token
secret gh-token set
$ graphenectl secret list
gh-token
kubeconfig
$ graphenectl secret delete gh-token
secret gh-token deleted

ns

graphenectl ns list
graphenectl ns create <name> [--retention-days <n>]

A graphene namespace is the isolation unit — symmetric to a Temporal namespace: records, queues, visibility, the ownership tree, all isolated by the durable core itself. Tokens are scoped to one namespace; ns verbs need an admin token.

FlagDefaultWhat it does
--retention-daysthe server default (30)closed-workflow retention
$ graphenectl ns list
default
team-b
$ graphenectl ns create team-b --retention-days 14
namespace team-b created