feat(secrets): rework command source as a registered SecretSource — no provider selector
Reworks the salvaged command module into a CommandSource(SecretSource) registered as the third bundled source, composing with Bitwarden and 1Password through the apply_all() orchestrator — enable any combination simultaneously. The original PR's secrets.provider single-selector is deliberately dropped: multi-source is first-class and a mutually exclusive provider switch would regress that. - fetch() only fetches; precedence/override/conflicts/environ writes stay in the orchestrator. ErrorKind classification + remediation hints. - apply_command_secrets() kept as a legacy shim (parser/security helpers unchanged: HERMES_SECRET_KEY data-only key passing, cross-key misroute guard, base64-padding disambiguation, timeout + output cap, structured- fields-only failure logging, stderr discarded). - Dispatch tests rewritten for the registry path incl. an explicit two-sources-compose test; selector tests removed with the selector. - cli-config.yaml.example + docs page (command.md), secrets index entry. - contributors mapping for mvalentin@valensys.net -> 0xr00tf3rr3t.
This commit is contained in:
@@ -1506,3 +1506,16 @@ updates:
|
||||
# binary_path: "" # "" = resolve op via PATH; else absolute path
|
||||
# cache_ttl_seconds: 300 # 0 disables BOTH cache layers
|
||||
# override_existing: true # resolved values win over existing env
|
||||
#
|
||||
# # ---- Command helper (any CLI vault) --------------------------------------
|
||||
# # Run a user-configured helper that prints KEY=VALUE lines on stdout —
|
||||
# # works with any secret store that has a CLI: keepassxc-cli, secret-tool,
|
||||
# # pass, gpg, or a script that cats a tmpfs env file. Composes with the
|
||||
# # sources above (enable any combination). POSIX-only (needs /bin/sh).
|
||||
# # The helper must be fast and NON-interactive (hard timeout, 1 MiB cap);
|
||||
# # its stderr is discarded so diagnostics can't leak secret material.
|
||||
# command:
|
||||
# enabled: false
|
||||
# command: "cat /run/user/1000/hermes-secrets.env"
|
||||
# helper_timeout_seconds: 3
|
||||
# override_existing: false # .env/shell win by default
|
||||
|
||||
Reference in New Issue
Block a user