Headless multi-application, multi-tenant secrets mangement engine.
Find a file
tegwick f87f4e5e4d refactor(catalog): explicit org/repo terminology; npm targets coulomb Gitea registry
Gitea's "project/package/release" terms are overloaded, so the catalog now uses
the most explicit words:
- org  = coulomb (the Gitea organisation)
- repo = whynot-design (the Gitea repository/product) — not an org, not a scope
- npm scope @whynot and package @whynot/design are distinct from both

Changes:
- catalog schema: replace conflated `owner` with required `org` + `repo`; `owner`
  is now a derived `org/repo` slug property
- npm-config delivery is data-driven: registry + scope live in
  delivery_config.npm and are validated; engine no longer hardcodes a registry
- exec delivery writes `<scope>:registry=<url>` + scoped `:_authToken` for the
  configured Gitea registry (token still env-expanded, never written to disk)
- pilot lane points at https://gitea.coulomb.social/api/packages/coulomb/npm/,
  scope @whynot, KV path coulomb/whynot-design/npm/publish
- npm-publish-demo uses @whynot scope so dry-run resolves the Gitea registry
- docs: terminology table; routing owner shown as coulomb/whynot-design
- tests: org/repo required, npm-config validation, registry authkey mapping

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-28 12:44:55 +02:00
.claude/rules feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00
.decisions feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00
catalog refactor(catalog): explicit org/repo terminology; npm targets coulomb Gitea registry 2026-06-28 12:44:55 +02:00
docs refactor(catalog): explicit org/repo terminology; npm targets coulomb Gitea registry 2026-06-28 12:44:55 +02:00
policies feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00
registry Initial commit 2026-06-28 09:03:37 +00:00
scripts refactor(catalog): explicit org/repo terminology; npm targets coulomb Gitea registry 2026-06-28 12:44:55 +02:00
src/secrets_engine refactor(catalog): explicit org/repo terminology; npm targets coulomb Gitea registry 2026-06-28 12:44:55 +02:00
tests refactor(catalog): explicit org/repo terminology; npm targets coulomb Gitea registry 2026-06-28 12:44:55 +02:00
workplans feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-06-28 11:27:44 +02:00
.gitignore feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00
.repo-classification.yaml feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00
AGENTS.md feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00
CLAUDE.md Initial commit 2026-06-28 09:03:37 +00:00
INTENT.md feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00
LICENSE Initial commit 2026-06-28 09:03:37 +00:00
ProductRequirementsDocument.md feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00
pyproject.toml feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00
README.md feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00
SCOPE.md feat(mvp): working secrets-engine CLI for the whynot-design npm publish lane 2026-06-28 12:28:45 +02:00

secrets-engine

Headless, multi-application, multi-tenant secrets workflow and automation layer for approved secret custody, delivery, and lifecycle work across build, test, and production stages.

OpenBao remains the custody and enforcement backend. secrets-engine owns the operator and agent interaction model: catalog, decision checks, plan/apply, safe provisioning, verification, delivery, evidence, rotation, and deactivation.

Start Here

Core Direction

The MVP proves the whynot-design-npm-publish lane end to end:

  1. describe the lane in a non-secret catalog (catalog/);
  2. verify an approved decision (State Hub or local fixture);
  3. apply OpenBao policy/auth metadata through a stage-aware role;
  4. provision and verify the value without printing it;
  5. run a workload command through safe exec-time delivery.

Target command shape:

secrets-engine exec --catalog whynot-design-npm-publish -- npm publish

Quickstart

uv venv && uv pip install -e ".[dev]"
source .venv/bin/activate
secrets-engine catalog list

# Run the whole pilot chain live against a throwaway OpenBao dev server:
SECRETS_ENGINE_HUB_URL="" bash scripts/demo-e2e.sh

The implementation is a Python package (src/secrets_engine/). OpenBao is reached only through the bao CLI adapter (openbao.py); the rest of the code speaks in lanes and guarded plans.

Security Rules

  • Do not put raw secret values in Git, State Hub, chat, prompts, issue comments, workplans, or normal logs.
  • OpenBao is the backend custody and audit authority.
  • Build, test, and production have separate policy boundaries.
  • Production actions require approved decisions except explicit break-glass flows.
  • Temporary bootstrap OpenBao credentials must live outside repos, use mode 0600, be revocable, and be removed after narrower auth is working.