Files
hermes-agent/agent/secret_sources/__init__.py
T
Teknium d4f2933262 refactor(agent/creds): unify secret-source CLI/cache/error plumbing in base and _cache
- base: run_cli (shared subprocess wrapper), classify_cli_error (rule tables),
  coerce_float, source_child_env, FetchResult.fail, SecretSource.token_env /
  token_env_key / default_token_env / override_existing_default so per-backend
  override_existing/protected_env_vars overrides collapse into the ABC;
  generic remediation is a kind->template table.
- _cache: atomic_write_json (mkstemp->0600->replace) and entry_from_payload
  shared by DiskCache and the bws encrypted cache; SecretCache = L1 dict + L2
  DiskCache with lookup/store/clear.
2026-09-02 13:29:46 -07:00

25 lines
935 B
Python

"""External secret source integrations.
A secret source supplies environment-variable-shaped credentials at process
startup, _after_ ~/.hermes/.env has loaded. The contract is
:class:`agent.secret_sources.base.SecretSource`; the orchestrator (ordering,
mapped-beats-bulk precedence, first-claim-wins, ``override_existing``,
provenance) is :func:`agent.secret_sources.registry.apply_all`. The
atomic-write / 0600 / TTL disk cache is shared in ``_cache``.
Bundled: ``bitwarden`` (bws CLI), ``onepassword`` (op CLI), ``command`` (user
helper). The set is deliberately closed — new third-party managers ship as
standalone plugin repos that subclass ``SecretSource`` and register through
``PluginContext.register_secret_source()``.
"""
from agent.secret_sources.base import ( # noqa: F401
SECRET_SOURCE_API_VERSION,
ErrorKind,
FetchResult,
SecretSource,
is_valid_env_name,
run_secret_cli,
scrub_ansi,
)