This repository has been archived on 2026-07-08. You can view files and clone it. You cannot open issues or pull requests or push a commit.
tegwick bcdfc78087 docs: seed SECRETS-WP-0004 (warden-sign lane); complete SCOPE.md sections
- SECRETS-WP-0004: scoped warden-sign OpenBao token lane for ops-warden, to
  unblock FLEX-WP-0007 T4 joint smoke. First auth-capability (non-KV) lane and
  first lane touching production OpenBao (bao.coulomb.social).
- SCOPE.md: add the standard sections flagged by the repo scope review (Relevant
  When, Not Relevant When, How It Fits, Terminology, Related / Overlapping,
  Provided Capabilities with fenced capability blocks); refresh Current State to
  reflect the delivered MVP.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-29 12:55:58 +02:00
2026-06-28 09:03:37 +00:00
2026-06-28 09:03:37 +00:00
2026-06-28 09:03:37 +00:00

secrets-engine

Headless, multi-application, multi-tenant secrets workflow and automation layer for approved secret custody, delivery, and lifecycle work across build, test, and production stages.

OpenBao remains the custody and enforcement backend. secrets-engine owns the operator and agent interaction model: catalog, decision checks, plan/apply, safe provisioning, verification, delivery, evidence, rotation, and deactivation.

Start Here

Core Direction

The MVP proves the whynot-design-npm-publish lane end to end:

  1. describe the lane in a non-secret catalog (catalog/);
  2. verify an approved decision (State Hub or local fixture);
  3. apply OpenBao policy/auth metadata through a stage-aware role;
  4. provision and verify the value without printing it;
  5. run a workload command through safe exec-time delivery.

Target command shape:

secrets-engine exec --catalog whynot-design-npm-publish -- npm publish

Quickstart

uv venv && uv pip install -e ".[dev]"
source .venv/bin/activate
secrets-engine catalog list

# Run the whole pilot chain live against a throwaway OpenBao dev server:
SECRETS_ENGINE_HUB_URL="" bash scripts/demo-e2e.sh

The implementation is a Python package (src/secrets_engine/). OpenBao is reached only through the bao CLI adapter (openbao.py); the rest of the code speaks in lanes and guarded plans.

Security Rules

  • Do not put raw secret values in Git, State Hub, chat, prompts, issue comments, workplans, or normal logs.
  • OpenBao is the backend custody and audit authority.
  • Build, test, and production have separate policy boundaries.
  • Production actions require approved decisions except explicit break-glass flows.
  • Temporary bootstrap OpenBao credentials must live outside repos, use mode 0600, be revocable, and be removed after narrower auth is working.
Description
Headless multi-application, multi-tenant secrets mangement engine.
Readme MIT-0 311 KiB
Languages
Python 90.5%
Shell 5.9%
HCL 3.6%