fix(secrets): backend-aware token checks; drop stale file-path assumptions
Post-migration sweep of legacy file-based secret code:
- deploy.py + doctor.py checked for the token *file* → false 'secret not found'
warnings now that tokens live in the vault; use read_secret (backend-aware)
- drop now-unused SECRETS_DIR imports
- refresh stale docstring/prompt text (${secret} 'reads ~/.castle/secrets' →
'via the active backend'; SecretsEditor add-prompt)
Kept (legitimate file paths): the bootstrap tier (OPENBAO_* token/unseal,
cloudflared creds dir) + the rendered 0600 env files.
This commit is contained in:
@@ -103,7 +103,7 @@ export function SecretsEditor({ secrets, onSecretsChange }: SecretsEditorProps)
|
||||
const handleAdd = () => {
|
||||
const envKey = prompt("Environment variable name (e.g. MY_API_KEY):")
|
||||
if (!envKey) return
|
||||
const secretName = prompt("Secret file name (stored in ~/.castle/secrets/):", envKey)
|
||||
const secretName = prompt("Secret name (in the active backend — file or vault):", envKey)
|
||||
if (!secretName) return
|
||||
onSecretsChange({ ...secrets, [envKey]: secretName })
|
||||
setStates((prev) => ({
|
||||
|
||||
Reference in New Issue
Block a user