d4f2933262
- base: run_cli (shared subprocess wrapper), classify_cli_error (rule tables), coerce_float, source_child_env, FetchResult.fail, SecretSource.token_env / token_env_key / default_token_env / override_existing_default so per-backend override_existing/protected_env_vars overrides collapse into the ABC; generic remediation is a kind->template table. - _cache: atomic_write_json (mkstemp->0600->replace) and entry_from_payload shared by DiskCache and the bws encrypted cache; SecretCache = L1 dict + L2 DiskCache with lookup/store/clear.
25 lines
935 B
Python
25 lines
935 B
Python
"""External secret source integrations.
|
|
|
|
A secret source supplies environment-variable-shaped credentials at process
|
|
startup, _after_ ~/.hermes/.env has loaded. The contract is
|
|
:class:`agent.secret_sources.base.SecretSource`; the orchestrator (ordering,
|
|
mapped-beats-bulk precedence, first-claim-wins, ``override_existing``,
|
|
provenance) is :func:`agent.secret_sources.registry.apply_all`. The
|
|
atomic-write / 0600 / TTL disk cache is shared in ``_cache``.
|
|
|
|
Bundled: ``bitwarden`` (bws CLI), ``onepassword`` (op CLI), ``command`` (user
|
|
helper). The set is deliberately closed — new third-party managers ship as
|
|
standalone plugin repos that subclass ``SecretSource`` and register through
|
|
``PluginContext.register_secret_source()``.
|
|
"""
|
|
|
|
from agent.secret_sources.base import ( # noqa: F401
|
|
SECRET_SOURCE_API_VERSION,
|
|
ErrorKind,
|
|
FetchResult,
|
|
SecretSource,
|
|
is_valid_env_name,
|
|
run_secret_cli,
|
|
scrub_ansi,
|
|
)
|