Skip to main content
All videos
q-ring0:32

q-ring 101 - rotate once, everywhere (qring entangle)

Link secrets with qring entangle so a new value written to one reaches its partners, even across projects. One rotation instead of a hunt.

Guide

What it does

qring entangle <source> <target> links two secrets. From then on, writing a new value to either one writes the same value to its partner. The link works in both directions and can cross projects, so the API key your web app and your background worker both use is set once instead of twice. qring disentangle removes the link.

Try it

# Link two keys in global scope
qring entangle API_KEY API_KEY_BACKUP

# Link the same key across two repositories
qring entangle API_KEY API_KEY --source-project . --target-project ../worker

# Rotate: a normal write propagates to the partner
qring set API_KEY

# Or rotate through the provider's own API, where it has one
qring rotate API_KEY

# See the links (no values), then undo them
qring inspect API_KEY
qring disentangle API_KEY API_KEY_BACKUP

Why it matters

A key that lives in three places gets rotated in two. The copy you forgot keeps working until it fails in production at 2 a.m., or worse, keeps the old, leaked value alive. Entanglement makes rotation a single action. Combined with --ttl or a rotation reminder (--rotate-every), it turns "we should rotate that" into something you can do in one command when the reminder comes due.

Gotchas and good to know

  • Without --source-project or --target-project, both keys are treated as global. Pass the project paths when the keys live in project scope.
  • Propagation reaches direct partners only. If A is linked to B and B to C, writing A updates B but not C. Link the keys you want updated together directly.
  • The partner has to exist already. Entangling does not create the target key, and a write skips a missing partner silently, so store both first.
  • Over MCP, a write will not propagate into a key the project's policy denies to agents. That stops entanglement from becoming a way around deniedKeys. Your own CLI writes are not restricted.
  • qring rotate goes through the provider's rotation API when one exists. Where it does not, rotation means writing the new value yourself, and the link still carries it.
  • The link registry lives in ~/.config/q-ring/entanglement.json. Secret values are never written there.

Go deeper

Transcript

Select a timestamp to start the video from that point.

  1. 0:01Rotating one key used to mean hunting down every copy.
  2. 0:07qring entangle links secrets together.
  3. 0:11Rotate one, and every entangled key follows.
  4. 0:16Instantly.
  5. 0:18One rotation.
  6. 0:20Everywhere at once.
  7. 0:23q-ring.
  8. 0:25Rotate once.