Deployment Manual / Version 2512.1
Table Of ContentsStartup fails on an undecryptable value. If the key is missing or wrong, the application does not start and reports
Cannot decrypt: key=<property name>. The message names the affected property but never its value. This is the desired behavior: without it, the cipher text itself would be passed on as if it were the password. Do not setencrypt.fail-on-errortofalsein production.No key rotation. There is no mechanism to roll over to a new key. Rotating it means re-encrypting every value with the new key and redeploying the configuration.
Per-application setup. Both the dependency and the key have to be added to every application that reads encrypted properties.
Do not mix it with the encryption service. This mechanism is unrelated to Chapter 4, Encryption Service Setup. It decrypts values in the Spring environment, whereas the encryption service decrypts the specific secrets that CoreMedia Content Cloud manages. Using both for the same value is not supported.


