Deployment Manual / Version 2512.1
Table Of Contents
The key is configured through the property encrypt.key. Supply it from
outside the versioned configuration, for example as the environment variable
ENCRYPT_KEY, which Spring Boot maps to that property. In a container
deployment, the platform or the operator injects it at deployment time.
The following table lists the most relevant properties.
| Property | Default | Description |
|---|---|---|
encrypt.key | The symmetric key used to encrypt and decrypt values. | |
encrypt.salt | deadbeef | Salt for the symmetric key, as a hex-encoded byte array. Changing it invalidates all existing cipher texts. |
encrypt.fail-on-error | true | Whether the application fails to start when a value cannot be decrypted. Keep the default, see Section 5.2.6, “Limitations and Operational Notes”. |
encrypt.key-store.* | Alternative to a symmetric key: an RSA key pair read from a Java keystore. See Section 5.2.5, “Using an RSA Key Pair from a Java Keystore”. |


