From a86557377c6c555a295258a617aaa7de7ebb4a44 Mon Sep 17 00:00:00 2001 From: robert Date: Wed, 7 Oct 2026 14:23:57 +1000 Subject: [PATCH] Document how sensitive variable passwords reach Calamari --- src/pages/docs/security/data-encryption.md | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/src/pages/docs/security/data-encryption.md b/src/pages/docs/security/data-encryption.md index aa19f6b3a1..53b662177f 100644 --- a/src/pages/docs/security/data-encryption.md +++ b/src/pages/docs/security/data-encryption.md @@ -1,7 +1,7 @@ --- layout: src/layouts/Default.astro pubDate: 2023-01-01 -modDate: 2024-10-04 +modDate: 2026-10-07 title: Data encryption description: This section describes how Octopus Deploy encrypts sensitive data at rest. navOrder: 50 @@ -35,6 +35,10 @@ The practical impact of this is: Without keeping a record of your Master Key, you won't be able to make use of your Octopus database backups, since there is no way to decrypt these sensitive values. ::: +## Sensitive variables on deployment targets {#sensitive-variables-on-targets} + +Octopus sends sensitive variables to a deployment target in encrypted form, and the target stores them encrypted. Octopus passes the password that decrypts them to the Calamari invocation as a process parameter. + ## Your Master Key {#your-master-key} When Octopus is installed, it generates a random string which will be used as the Master Key. You will need to know your Master Key if you ever hope to restore an Octopus backup on another server.