Skip to content

Commit 03f3791

Browse files
feat(secrets): secrets ingest — .env → SOPS/provider secrets + vars (spec 24) (#82)
Add the write half of the secrets boundary and a new envingest pipeline that gets committed .env files out of the repo: - internal/secrets: Pusher capability (SecretEntry/Pusher) on aws-sm/aws-ssm/ infisical (values via stdin/env, never logged argv), a stdin-capable runner (OutputStdin), and SOPS encrypt/decrypt helpers that shell `sops` over stdin (no Go SDK, no plaintext temp file). - internal/envingest: parse (compose-go dotenv) → classify default-deny (glob → name → value heuristics → benign → default secret) → route (sops file / remote Pusher) → encrypt/push → compute secret:// refs → rewrite the target devstack.yaml env block in place via the goccy AST (comment/order preserving) → scaffold a sops provider into workspace.yaml when absent → round-trip verify before deleting → fence .env in .gitignore → delete (or --keep-env). Idempotency via decrypt-and-compare; no flock. - internal/cli: `secrets ingest [<.env>]` with --to/--dest/--service/ --recipient/--secret/--public/--from-host/--prefixed/--keep-env/--dry-run/ --yes/--force/--json + a degradable huh v2 classification wizard gated on prompt.IsInteractive. - Tests: Pusher argv/stdin per provider, classify ladder, AST rewrite/scaffold, full-run leak test, git-tracked refusal, dry-run writes nothing, decrypt- compare idempotency, non-TTY gate routes to the flag path. Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
1 parent eaf4694 commit 03f3791

12 files changed

Lines changed: 2543 additions & 0 deletions

‎internal/cli/secrets.go‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,7 @@ func newSecretsCmd(g *GlobalOpts) *cobra.Command {
2020
}
2121
cmd.AddCommand(
2222
newSecretsKeygenCmd(g),
23+
newSecretsIngestCmd(g),
2324
newSecretsLoginCmd(g),
2425
newSecretsLogoutCmd(g),
2526
newSecretsStatusCmd(g),

0 commit comments

Comments
 (0)