Headless multi-application, multi-tenant secrets mangement engine.
Find a file
tegwick 9f56c88c96
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
fix(workplans): qualify ad-hoc identifiers with the repository prefix
`ADHOC-YYYY-MM-DD` is unique per date but not per repository, so any two repos
opening an ad-hoc on the same day collide. The 2026-08-26 fleet projection
reset refused 9 records for exactly this reason.

Canon (work-record-types_v0.1, CUST-WP-0066) settled the form as
`{PREFIX}-WP-ADHOC-YYYY-MM-DD`, filename unchanged, and grandfathered existing
ids on the condition they are never *silently* re-derived. This is the explicit
migration that clause allows for.

The hub id is derived from the record id, so a changed id is a different
record: stale state_hub_*_id fields are dropped and fix-consistency re-derives.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-28 00:28:23 +02:00
.claude/rules docs: workplan-first agent guidance prose (CUST-WP-0055 T04 batch 4) 2026-07-08 17:22:20 +02:00
.decisions Document scope alignment and warden-sign readiness 2026-06-30 00:52:05 +02:00
.forgejo/workflows Add Forgejo CI smoke workflow (enablement template) 2026-07-08 12:37:57 +02:00
catalog feat: admit existing OpenBao catalog lanes 2026-08-21 08:20:33 +02:00
docs Harden production authorization and service auth 2026-08-23 14:15:42 +02:00
history docs: align scope with implemented capabilities 2026-08-23 10:48:16 +02:00
policies Harden secret provisioning and lifecycle controls 2026-08-23 12:05:58 +02:00
registry Initial commit 2026-06-28 09:03:37 +00:00
scripts Harden production authorization and service auth 2026-08-23 14:15:42 +02:00
src/secrets_engine Harden production authorization and service auth 2026-08-23 14:15:42 +02:00
tests Harden production authorization and service auth 2026-08-23 14:15:42 +02:00
workplans fix(workplans): qualify ad-hoc identifiers with the repository prefix 2026-08-28 00:28:23 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-08-25 17:51:43 +02:00
.gitignore feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00
.repo-classification.yaml feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00
AGENTS.md docs(agents): repoint remote State Hub URL to the in-cluster address 2026-08-25 00:22:03 +02:00
CLAUDE.md Regenerate agent instructions from state-hub templates (CUST-WP-0055 T01) 2026-07-08 14:50:36 +02:00
INTENT.md Document scope alignment and warden-sign readiness 2026-06-30 00:52:05 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-30 01:04:47 +02:00
ProductRequirementsDocument.md Add value-safe verification and audit reporting 2026-08-23 12:33:38 +02:00
pyproject.toml feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00
README.md Harden production authorization and service auth 2026-08-23 14:15:42 +02:00
SCOPE.md Harden production authorization and service auth 2026-08-23 14:15:42 +02:00
uv.lock Document scope alignment and warden-sign readiness 2026-06-30 00:52:05 +02:00
WORK-RECORDS.md Harden production authorization and service auth 2026-08-23 14:15:42 +02:00

secrets-engine

Headless, multi-application, multi-tenant secrets workflow and automation layer for approved secret custody, delivery, and lifecycle work across build, test, and production stages.

OpenBao remains the custody and enforcement backend. secrets-engine owns the operator and agent interaction model: catalog, decision checks, plan/apply, guarded provisioning, verification, delivery, evidence, lifecycle metadata, and native-access deactivation. Local evidence can be inspected through an allowlisted per-lane audit summary without exposing record detail.

Start Here

Core Direction

The MVP proves the whynot-design-npm-publish lane end to end:

  1. describe the lane in a non-secret catalog (catalog/);
  2. verify an approved decision (State Hub or local fixture);
  3. apply OpenBao policy/auth metadata through a stage-aware role;
  4. provision and verify the value without printing it;
  5. run a workload command through safe exec-time delivery.

Target command shape:

secrets-engine exec --catalog whynot-design-npm-publish -- npm publish

Quickstart

uv venv && uv pip install -e ".[dev]"
source .venv/bin/activate
secrets-engine catalog list

# Run the whole pilot chain live against a throwaway OpenBao dev server:
SECRETS_ENGINE_HUB_URL="" bash scripts/demo-e2e.sh

The implementation is a Python package (src/secrets_engine/). OpenBao is reached only through the bao CLI adapter (openbao.py); the rest of the code speaks in lanes and guarded plans.

Security Rules

  • Do not put raw secret values in Git, State Hub, chat, prompts, issue comments, workplans, or normal logs.
  • OpenBao is the backend custody and audit authority.
  • Build, test, and production have separate policy boundaries.
  • Production live actions fail closed until the durable State Hub action-authorization endpoint is available; local approval mirrors are throwaway-demo material only.
  • Temporary bootstrap OpenBao credentials must live outside repos, use mode 0600, be revocable, and be removed after narrower auth is working.