webhook add takes the signing secret on argv: --secret <s> (internal/control/webhook.go:16-23). Secrets are meant to travel on stdin only, because argv shows up in /proc on the client and in shell history.
- Read the secret from stdin (
--secret -,ReadsStdin: true) and refuse a literal value, the wayrepo secret setdoes. - Update the web form handler if it builds the argv with the secret, and the API wiki page.
referenced in commit fb6e9dcfa4 by cmc: plans: #287, #284, #298, #285, #297
2026-09-29 00:09 UTC