Commit 03f3791
feat(secrets):
Add the write half of the secrets boundary and a new envingest pipeline that
gets committed .env files out of the repo:
- internal/secrets: Pusher capability (SecretEntry/Pusher) on aws-sm/aws-ssm/
infisical (values via stdin/env, never logged argv), a stdin-capable runner
(OutputStdin), and SOPS encrypt/decrypt helpers that shell `sops` over stdin
(no Go SDK, no plaintext temp file).
- internal/envingest: parse (compose-go dotenv) → classify default-deny
(glob → name → value heuristics → benign → default secret) → route (sops
file / remote Pusher) → encrypt/push → compute secret:// refs → rewrite the
target devstack.yaml env block in place via the goccy AST (comment/order
preserving) → scaffold a sops provider into workspace.yaml when absent →
round-trip verify before deleting → fence .env in .gitignore → delete (or
--keep-env). Idempotency via decrypt-and-compare; no flock.
- internal/cli: `secrets ingest [<.env>]` with --to/--dest/--service/
--recipient/--secret/--public/--from-host/--prefixed/--keep-env/--dry-run/
--yes/--force/--json + a degradable huh v2 classification wizard gated on
prompt.IsInteractive.
- Tests: Pusher argv/stdin per provider, classify ladder, AST rewrite/scaffold,
full-run leak test, git-tracked refusal, dry-run writes nothing, decrypt-
compare idempotency, non-TTY gate routes to the flag path.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>secrets ingest — .env → SOPS/provider secrets + vars (spec 24) (#82)1 parent eaf4694 commit 03f3791
12 files changed
Lines changed: 2543 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
| 23 | + | |
23 | 24 | | |
24 | 25 | | |
25 | 26 | | |
| |||
0 commit comments