telegraf secrets remove

The telegraf secrets remove command removes a secret from a specified secret store. Removing a key that does not exist in the store results in an error.

Not all secret stores support modifying secrets. Stores backed by a read-only source reject the set and remove commands.

This command requires your configuration file that contains the secret store definitions you want to access. If the --config or --config-directory flags are not included in the command, Telegraf checks the default configuration file location.

Use telegraf secrets list to get the IDs of available secret stores and the available secret keys.

If you haven’t configured a secret store, use telegraf plugins secretstores to list available secret store plugins. View secret store plugin configuration documentation in the Telegraf GitHub repository.

Usage

telegraf [global-flags] secrets remove [flags] <SECRET_STORE_ID> <SECRET_KEY>

Arguments

ArgumentDescription
SECRET_STORE_IDID of the secret store to remove the secret from
SECRET_KEYKey of the secret to remove

Flags

FlagDescription
-h--helpShow command help

Examples

In the examples below, replace the following:

  • SECRET_STORE_ID: The ID of the secret store to remove the secret from.
  • SECRET_KEY: The key of the secret to remove.
  • CUSTOM_CONFIG_PATH: The non-default filepath to your Telegraf configuration file containing your secret store definitions.

Remove a secret using the default configuration location

The following example assumes the Telegraf configuration file that contains the secret store definition is at the default location.

telegraf secrets remove 
SECRET_STORE_ID
SECRET_KEY

Remove a secret using a non-default configuration location

telegraf \
  --config 
CUSTOM_CONFIG_PATH
\
secrets remove \
SECRET_STORE_ID
\
SECRET_KEY

Was this page helpful?

Thank you for your feedback!