TL;DR: zitadel-encryption-key-secret-dev feeds NEXTGEN_SERVER_ENCRYPTION_KEY, a config key the server no longer has. Once the new deployment is serving, delete the secret and stop paying attention to it. Found while probing the dev project for #1132.
Problem
The dev project holds two Secret Manager secrets created on 2026-06-07, outside OpenTofu:
zitadel-encryption-key-secret-dev
zitadel-postgres-secret-dev
The Cloud Run service still consumes both, as NEXTGEN_SERVER_ENCRYPTION_KEY and NEXTGEN_DATABASE_POSTGRES. The running revision is a June build from the abandoned infra branch (0.0.1-snapshot-8c78c632).
NEXTGEN_SERVER_ENCRYPTION_KEY no longer exists in the server's configuration surface — it was replaced by the rotatable master-key config (server.master_keys), which is a map and cannot be populated from an environment variable at all. So the secret is inert for any current build: a server reading it would ignore it.
#1132 creates differently named secrets (zitadel-master-key-dev, zitadel-database-postgres-dev) rather than adopting these, so after the cutover the old pair is orphaned.
What to do
After the new deployment is confirmed serving:
- Delete
zitadel-encryption-key-secret-dev — it feeds a key that does not exist.
- Decide on
zitadel-postgres-secret-dev. Its value is still valid (the DSN for the same instance), so it may be worth reading once to seed DATABASE_POSTGRES_DSN in the GitHub dev environment rather than reconstructing the DSN by hand. Delete it afterwards.
Data loss across the cutover has been accepted, so nothing encrypted under the old key needs migrating.
Related
Fix after these are merged:
TL;DR:
zitadel-encryption-key-secret-devfeedsNEXTGEN_SERVER_ENCRYPTION_KEY, a config key the server no longer has. Once the new deployment is serving, delete the secret and stop paying attention to it. Found while probing the dev project for #1132.Problem
The dev project holds two Secret Manager secrets created on 2026-06-07, outside OpenTofu:
zitadel-encryption-key-secret-devzitadel-postgres-secret-devThe Cloud Run service still consumes both, as
NEXTGEN_SERVER_ENCRYPTION_KEYandNEXTGEN_DATABASE_POSTGRES. The running revision is a June build from the abandoned infra branch (0.0.1-snapshot-8c78c632).NEXTGEN_SERVER_ENCRYPTION_KEYno longer exists in the server's configuration surface — it was replaced by the rotatable master-key config (server.master_keys), which is a map and cannot be populated from an environment variable at all. So the secret is inert for any current build: a server reading it would ignore it.#1132 creates differently named secrets (
zitadel-master-key-dev,zitadel-database-postgres-dev) rather than adopting these, so after the cutover the old pair is orphaned.What to do
After the new deployment is confirmed serving:
zitadel-encryption-key-secret-dev— it feeds a key that does not exist.zitadel-postgres-secret-dev. Its value is still valid (the DSN for the same instance), so it may be worth reading once to seedDATABASE_POSTGRES_DSNin the GitHubdevenvironment rather than reconstructing the DSN by hand. Delete it afterwards.Data loss across the cutover has been accepted, so nothing encrypted under the old key needs migrating.
Related
Fix after these are merged: