Credentials and governance
Credential references
Section titled “Credential references”hyperlake creds listhyperlake creds create --name NAME --value-stdinhyperlake creds create --name NAME --value-env ENV_VARhyperlake creds update --id CREDENTIAL_ID --value-env ENV_VARListing returns metadata and references, never the credential value. Prefer --value-stdin, --value-env, or --value-file over --value so secrets do not enter shell history.
Catalog grants
Section titled “Catalog grants”hyperlake catalog grants listhyperlake catalog grants create --catalog CATALOG --member-email EMAIL --operations SELECThyperlake catalog grants test --cluster CLUSTER_ID --sql SQL --as-member-email EMAILhyperlake catalog grants status --cluster CLUSTER_IDhyperlake catalog grants sync --cluster CLUSTER_IDGrant tests evaluate a query under a selected test identity through the authorized policy-test path. They are not a way to retrieve another user’s credentials.