CLI command
probierz protect
Encrypt one run's artifact bundle at rest and optionally remove the plaintext source artifacts.
Invocation#
probierz protect [APP_ID] [RUN_ID] [KIND]Required inputs and options#
- `<appId>` and `<runId>` are required. `[kind]` optionally names the bundle kind.
- A 32-byte encryption key is required through `--key-file <path>` or `PROBIERZ_ARTIFACT_ENCRYPTION_KEY_FILE`; `--remove-source` requests plaintext removal after protection succeeds.
Output and state effects#
Creates the protected bundle, records protection metadata, and writes the result as JSON. Plaintext is removed only when explicitly requested and after a successful bundle operation.
Exact refusals#
- Missing identity: `protect needs an app ID and run ID`.
- If present without a path, `--key-file` is refused as `--key-file needs a path`.
- Missing runs, unsafe keys, secret-scan/persistence failures, or encryption errors propagate; source removal is not used as a fallback.
Source snapshot#
Generated from the Rust binaries at https://github.com/wisent-ai/probierz.git revision `f40fa7ed94a028b56b5a59342eaf55982ba5cf7d`.
Combined help SHA-256: `04bab0ac1e9691119efcb70627b534a73431f51bb44ed8ba81d93cc10afd6569`; binary SHA-256: `08424ee2465261eafaa112d13ef05a20ce1fe1b6479e896341e22fbc55e61d3e`.