Registry stack documentation: machine-readable Markdown.
Index of all pages: https://docs.registrystack.org/dev/llms.txt
Full corpus: https://docs.registrystack.org/dev/llms-full.txt

# bregctl field-encryption command reference

> Generated syntax and options for bregctl field-encryption.

{/* Generated from Clap command definitions by scripts/generate-cli-reference.mjs. Run npm run generate. */}

Maintain field-encryption key material.

## Contract status

This page is generated from the public Clap command tree for Registry Stack source version `0.34.0` and catalog SHA-256 `c9eb944fbb64b3beca0250dc0dee945ea12d5c5f92ffeab2f7c21d9eeb888c6c`. Hidden implementation commands are omitted.

## Usage

```text
bregctl field-encryption [OPTIONS] <COMMAND>
```

## Commands

| Command | Description |
| --- | --- |
| [`keygen`](./keygen/) | Write one fresh base64 data key for the local-file provider. The key never reaches standard output and an existing file is never overwritten |
| [`preflight`](./preflight/) | Report what one reviewed backfill apply would do, before running it: value-free counts per covered field, the descriptor's explicit history choice, and the record names a unique blind index would refuse |
| [`erase-history`](./erase-history/) | Erase the retained plaintext history of flips that declared erase-and-rebaseline, then restore snapshot coverage with one rebaseline. Runs only after the flip's package is active |

## Options

| Option | Always required | Default | Values | Environment | Description |
| --- | --- | --- | --- | --- | --- |
| `--format <FORMAT>` | No | `human` | `human`, `json` | n/a | Emit the selected command's report in this format |
| `-h, --help` | No | n/a | n/a | n/a | Print help |

## Generation contract

Run `npm run generate` from `docs/site` after changing a public command, argument, option, default, environment binding, or help description.