Weekly Doppler stale secret triage to Jira and Slack

By General Input

Every Monday at 8am, find the riskiest stale secrets in your production Doppler configs, file Jira rotation tickets, and post a digest to Slack.

Integrations

  • Doppler
  • Jira
  • Slack

Type

Agentic Task

Categories

  • Engineering

Every Monday at 8am in my timezone, run a stale secret rotation triage across my Doppler workplace and turn it into a prioritized Jira backlog plus a Slack digest.

Trigger: cron, weekly on Monday at 8am.

Step 1, map the workplace. Use Doppler List Projects to enumerate every project. For each project, use Doppler List Environments and Doppler List Configs to find every production-like config. Treat anything in a production environment (prd, prod, production) as in scope. Skip development and branch configs on the first pass unless every production config already looks clean.

Step 2, gather signals. For each in-scope config, use Doppler List Secret Names to enumerate the secrets, and use Doppler List Config Logs to read the change history. From the logs, work out the last-changed timestamp per secret. Never request the actual secret values.

Step 3, score risk. Build a per-secret score that favors anything unchanged for 90 or more days in a production environment. Increase the weight for high-blast-radius name patterns, including DATABASE_URL, STRIPE_, AWS_, OAUTH_, JWT_, ROOT, and ADMIN. Drop low-signal infrastructure defaults like NODE_ENV, PORT, LOG_LEVEL, and similar non-secret config. Pick the top rotation candidates for the week, aiming for a manageable number rather than every single hit.

Step 4, file Jira tickets. For each rotation candidate, use Jira Create Issue in a configurable security or platform project. If there are many candidates, use Jira Create Issues Bulk instead. Each ticket should have a clear summary like "Rotate STRIPE_SECRET_KEY in payments / prod", a body that explains why it surfaced (days since last change, environment, evidence from the config logs), and a checklist of rotation steps (generate a new value in the upstream provider, update the Doppler secret, verify the deploy, revoke the old value). Never put secret values in the ticket body.

Step 5, post the Slack digest. Use Slack Send a Message to post to a configurable security or platform channel. Include the total count of stale production secrets, the top five worst offenders by score with their new Jira ticket links, and a one line week-over-week comparison if there is prior context to draw on. Keep the tone calm and operational, never alarmist. Do not include any secret values.

Configurables to expose: the Doppler token, the Jira destination project key, the Slack channel, the staleness threshold in days (default 90), and the maximum number of tickets to file per run.

Related prompts

Explore more prompts
Call overdue Xero customers with an AI collections agentWin back LiveChat visitors whose chats went unansweredChat quality review board for LiveChat support leadsWin back no-show and cancelled appointments every morningLive Loop returns analytics with product-level drill-downNewsletter pre-flight and approval board for Mailjet sendsTurn a prospect spreadsheet into personalized sequence enrollmentsMailjet email delivery lookup console for support teamsCatch feature flags that never got switched on in productionKajabi customer support console for member access fixes