mirror of
https://github.com/profullstack/logicsrc.git
synced 2026-10-05 14:15:33 +00:00
vault + teams: filter secrets by category, export to CSV, simpler help (#195)
Every secret now has a category derived from its name (db, social, server,
api, cloud, finance, crypto, ai, email, messaging, storage, dns, analytics,
devtools, auth, config, other). One rule table in @logicsrc/opencreds serves
both vaults; services win over generic words, so STRIPE_WEBHOOK_SECRET is
finance, not auth. Checked against the 1,208 distinct key names in the
profullstack team: 74 fall to "other".
Team vaults (where the shared .env secrets live):
- teams categories [team] the filter words, with per-category counts
- teams secrets <team> [project] [env] --category/-c --search/-s
names + categories, never decrypts; --format csv
- teams export <team> [project] [env] --category -o file.csv [--yes]
decrypts into team,project,env,category,key,
value,updated_at (0600); skips vaults without a
grant and names them
Personal vault (OpenCreds):
- vault list --category, and the category column in list output
- vault export --format csv: one flat row per item, keeps key/account
secrets that a Bitwarden CSV drops; --category on every export format
DX:
- examples in `logicsrc vault help` / -h / --help that start by saying which
of the two vaults you want, plus examples on teams and each subcommand
- password prompts go to stderr, so eval "$(logicsrc vault unlock)" works
- hints name the command you actually ran (logicsrc vault init, not
opencreds init)
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
156c9164a9
commit
3d155af970
11 changed files with 846 additions and 19 deletions
|
|
@ -18,13 +18,46 @@ import { registerCredsCommands } from "@logicsrc/opencreds/commands";
|
|||
* account — encrypted end to end and portable as one file rather than a
|
||||
* plaintext CSV. They meet at the `key` item: a synced .env entry, stored.
|
||||
*/
|
||||
export const VAULT_GUIDE = `
|
||||
There are two vaults. Pick the one you need:
|
||||
|
||||
Team secrets .env keys shared with your team (DATABASE_URL, STRIPE_SECRET_KEY, …)
|
||||
-> logicsrc teams … (this is where the company secrets are)
|
||||
Personal vault your own logins, cards, SSH keys, notes
|
||||
-> logicsrc vault …
|
||||
|
||||
Team secrets, the everyday commands:
|
||||
logicsrc login once per machine
|
||||
logicsrc teams list the teams you are in
|
||||
logicsrc teams secrets <team> every secret name + its category
|
||||
logicsrc teams secrets <team> --category db only database secrets
|
||||
logicsrc teams secrets <team> -s stripe names containing "stripe"
|
||||
logicsrc teams export <team> --category db -o db.csv decrypt them into a CSV
|
||||
logicsrc teams pull <team> <project> <env> write one vault into ./.env
|
||||
logicsrc teams categories db, social, server, api, cloud, …
|
||||
|
||||
Personal vault:
|
||||
logicsrc vault init create it (once)
|
||||
eval "$(logicsrc vault unlock)" unlock for this shell
|
||||
logicsrc vault add login --name GitHub --username me --password -
|
||||
logicsrc vault list --category social never shows values
|
||||
logicsrc vault get GitHub --field login.password --reveal
|
||||
logicsrc vault export --format csv --category db --out db.csv --yes
|
||||
logicsrc vault import bitwarden.csv
|
||||
|
||||
Help for any command: logicsrc vault <command> --help (or: logicsrc vault help <command>)
|
||||
`;
|
||||
|
||||
export function registerOpenCredsCommands(program: Command): void {
|
||||
const vault = program
|
||||
.command("vault")
|
||||
.description(
|
||||
"OpenCreds: an end-to-end-encrypted vault for logins, cards, identities, notes, keys " +
|
||||
"and accounts, portable as one file. Also available as the standalone `opencreds` command.",
|
||||
);
|
||||
"Your personal encrypted vault (logins, cards, keys, notes). " +
|
||||
"Team .env secrets are under `logicsrc teams` — examples below.",
|
||||
)
|
||||
// Most people typing `logicsrc vault` want the TEAM secrets, which live
|
||||
// under `teams`. Say so first, with commands they can paste.
|
||||
.addHelpText("after", VAULT_GUIDE);
|
||||
|
||||
registerCredsCommands(vault);
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue