rotated secret still referenced in env file: cleanup failed
Cleans up env files still referencing a rotated secret after rotation. Finds every stale reference and repoints it. Use after any rotation where apps keep reading old values. Not for secrets-manager-backed apps (no env file involved).
TL;DR
Rotation changed the credential but the env file still carries the old reference or value. Search every env file for the old identifier, update it to the new reference, and restart the consumers so the change takes effect.
Error
rotated secret still referenced in env file: cleanup failedSteps
- Search all env files for the old value's distinctive prefix or the variable name. Expected: every file that references it.
- Determine whether the file holds the value inline (update the value) or a reference (update the pointer). Expected: you know which kind each file is.
- Replace with the new value or reference; prefer references to a secret manager over inline values. Expected: no stale references remain.
- Restart or reload every service that reads those files; env files are read at startup. Expected: services pick up the new value.
- Verify by checking the running config, not just the file. Expected: the live value matches the new credential.
When to use
- Post-rotation breakage traced to env files.
- Auditing for leftover references.
When not to use
- Apps that read from a secret manager directly (check the manager, not env files).
- The old value was never in an env file (search config and code instead).
Tool compatibility
- Dotenv-style files; any runtime.
Variant phrasings
old secret still in .env after rotation
Same cleanup.
app reading old env value
Restart after updating.
Why it happens
Env files are static snapshots copied across machines and repos; rotation updates the source of truth but not the copies.
Edge cases
- Env files checked into git need the same treatment in every branch and clone.
- Container images bake env files in; rebuild the image, not just the file.
- Some frameworks cache env at build time; a restart is not enough, rebuild.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_ploMg7OLG5KU3SNZufyvIA