getsops/sops · error

failed to decrypt sops data key with pgp: %s

Error message

failed to decrypt sops data key with pgp: %s

What it means

Error "failed to decrypt sops data key with pgp: %s" thrown in getsops/sops.

Source

Thrown at pgp/keysource.go:455

		return nil, fmt.Errorf("reading PGP message failed: %s", err)
	}
	if b, err := io.ReadAll(md.UnverifiedBody); err == nil {
		return b, nil
	}
	return nil, fmt.Errorf("the key could not be decrypted with any of the PGP entries")
}

// decryptWithGnuPG attempts to obtain the data key from the EncryptedKey using
// GnuPG and returns the result. If DisableAgent is configured on the MasterKey,
// the GnuPG agent is not enabled. When the decryption command fails, it returns
// the error from stdout.
func (key *MasterKey) decryptWithGnuPG(ctx context.Context) ([]byte, error) {
	args := []string{
		"-d",
	}
	stdout, stderr, err := gpgExec(ctx, key.gnuPGHomeDir, args, strings.NewReader(key.EncryptedKey))
	if err != nil {
		return nil, fmt.Errorf("failed to decrypt sops data key with pgp: %s",
			strings.TrimSpace(stderr.String()))
	}
	result := stdout.Bytes()
	if len(result) == 0 {
		// This can happen if an older GnuPG version is used to decrypt a key encrypted with a
		// newer GnuPG version that used an AEAD cipher, which the old version does not support.
		// Apparently some GnuPG versions drop the unspuported packets, which results in a decrypted
		// data of 0 bytes, and returns nothing with exit code 0.
		//
		// (See https://github.com/getsops/sops/issues/896#issuecomment-2688079300 for more infos.)
		return nil, fmt.Errorf("failed to decrypt sops data key with pgp: zero bytes returned")
	}
	return result, nil
}

// NeedsRotation returns whether the data key needs to be rotated
// or not.
func (key *MasterKey) NeedsRotation() bool {

View on GitHub (pinned to 13442bb981)

When it happens

Trigger: Thrown at pgp/keysource.go:455 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of getsops/sops@13442bb981 (2026-09-01). Data as JSON: /api/errors/e390f501e7bbac98. Report an issue: GitHub.