Skip to content

Skip files without a matching destination rule in recursive publish - #2305

Open
somaz94 wants to merge 1 commit into
getsops:mainfrom
somaz94:fix/recursive-publish-skip-unmatched
Open

somaz94 wants to merge 1 commit into
getsops:mainfrom
somaz94:fix/recursive-publish-skip-unmatched

Conversation

@somaz94

@somaz94 somaz94 commented Sep 28, 2026

Copy link
Copy Markdown

Fixes #1620.

sops publish --recursive stops at the first file that no destination rule matches, so every file the walk reaches after it is never published. With the layout from the issue, project/a/prod/parameters.yml aborts the run and project/b/base/credentials.enc.yml is left out.

In recursive mode such a file is now skipped with a message, the same way a file declined at the interactive prompt already is. Publishing a single file still fails as before. config exports ErrNoMatchingDestination so the publish command can tell this case apart; the error text is unchanged.

Two misconfigurations used to hit the same error, and I did not want them to turn into a run that skips every file and exits 0, so they now return their own errors: a config with no destination rules at all, and a destination path_regex that does not compile (it was treated as a non-match, while creation rules already report it).

Validation: go test ./... passes on Go 1.26.1 and the changed packages pass on Go 1.25.8. Against a Vault 1.14.0 dev server with the directory layout from the issue, main publishes one of the two files and exits 1, and this branch publishes both and exits 0.

Signed-off-by: somaz <genius5711@gmail.com>
somaz94 added a commit to somaz94/somaz94 that referenced this pull request Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

no matching destination found in config when publishing to vault if directory have other files

1 participant