Skip to content

Retire zitadel-encryption-key-secret-dev: it feeds a config key that no longer exists #1165

Description

@muhlemmer

TL;DR: zitadel-encryption-key-secret-dev feeds NEXTGEN_SERVER_ENCRYPTION_KEY, a config key the server no longer has. Once the new deployment is serving, delete the secret and stop paying attention to it. Found while probing the dev project for #1132.

Problem

The dev project holds two Secret Manager secrets created on 2026-06-07, outside OpenTofu:

  • zitadel-encryption-key-secret-dev
  • zitadel-postgres-secret-dev

The Cloud Run service still consumes both, as NEXTGEN_SERVER_ENCRYPTION_KEY and NEXTGEN_DATABASE_POSTGRES. The running revision is a June build from the abandoned infra branch (0.0.1-snapshot-8c78c632).

NEXTGEN_SERVER_ENCRYPTION_KEY no longer exists in the server's configuration surface — it was replaced by the rotatable master-key config (server.master_keys), which is a map and cannot be populated from an environment variable at all. So the secret is inert for any current build: a server reading it would ignore it.

#1132 creates differently named secrets (zitadel-master-key-dev, zitadel-database-postgres-dev) rather than adopting these, so after the cutover the old pair is orphaned.

What to do

After the new deployment is confirmed serving:

  1. Delete zitadel-encryption-key-secret-dev — it feeds a key that does not exist.
  2. Decide on zitadel-postgres-secret-dev. Its value is still valid (the DSN for the same instance), so it may be worth reading once to seed DATABASE_POSTGRES_DSN in the GitHub dev environment rather than reconstructing the DSN by hand. Delete it afterwards.

Data loss across the cutover has been accepted, so nothing encrypted under the old key needs migrating.

Related

Fix after these are merged:

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    Priority

    None yet

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions