Add castle secret CLI and fail-loud unresolved-secret apply gate
Writing a secret by hand meant knowing the active backend and its layout;
getting it wrong (a file write on an OpenBao fleet) left the value where the
resolver never reads it, so ${secret:NAME} silently degraded to the literal
<MISSING_SECRET:NAME> placeholder that a service then used as its credential.
- `castle secret {list|set|get|rm}` reads/writes the ACTIVE backend, so there's
no wrong store to pick. `set NAME` with no value reads a hidden prompt / stdin.
- `castle apply` (and --plan) now refuses to converge any deployment whose
${secret:...} refs don't resolve in the active backend: exits non-zero, writes
nothing, and names each deployment + secret + the `castle secret set` fix.
- New helpers in core/config.py: active_secret_backend(), active_backend_name(),
secret_refs(). Gate impl: deploy._unresolved_secrets() + ApplyResult.blocked.
- Tests: test_deploy_secret_gate.py, TestSecretRefs, test_secret.py. Docs: AGENTS.md.
This commit is contained in:
56
cli/tests/test_secret.py
Normal file
56
cli/tests/test_secret.py
Normal file
@@ -0,0 +1,56 @@
|
||||
"""Tests for the `castle secret` command (reads/writes the active backend)."""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
from argparse import Namespace
|
||||
from pathlib import Path
|
||||
|
||||
import pytest
|
||||
|
||||
|
||||
@pytest.fixture
|
||||
def file_secrets(tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> Path:
|
||||
"""Force the active backend to a temp file store."""
|
||||
secrets = tmp_path / "secrets"
|
||||
secrets.mkdir()
|
||||
monkeypatch.setenv("CASTLE_SECRET_BACKEND", "file")
|
||||
monkeypatch.setattr("castle_core.config.SECRETS_DIR", secrets)
|
||||
return secrets
|
||||
|
||||
|
||||
def _run(**kw: object) -> int:
|
||||
from castle_cli.commands.secret import run_secret
|
||||
|
||||
return run_secret(Namespace(**kw))
|
||||
|
||||
|
||||
class TestSecretRoundtrip:
|
||||
def test_set_get_list_rm(self, file_secrets: Path, capsys: object) -> None:
|
||||
assert _run(secret_command="set", name="MY_KEY", value="s3cret") == 0
|
||||
capsys.readouterr() # type: ignore[attr-defined] # drain the "Set …" line
|
||||
|
||||
assert _run(secret_command="get", name="MY_KEY") == 0
|
||||
assert capsys.readouterr().out.strip() == "s3cret" # type: ignore[attr-defined]
|
||||
|
||||
assert _run(secret_command="list") == 0
|
||||
assert "MY_KEY" in capsys.readouterr().out # type: ignore[attr-defined]
|
||||
|
||||
assert _run(secret_command="rm", name="MY_KEY", yes=True) == 0
|
||||
# Gone → non-zero.
|
||||
assert _run(secret_command="get", name="MY_KEY") == 1
|
||||
|
||||
|
||||
class TestSecretEdges:
|
||||
def test_get_missing_is_nonzero(self, file_secrets: Path) -> None:
|
||||
assert _run(secret_command="get", name="ABSENT") == 1
|
||||
|
||||
def test_empty_value_refused(self, file_secrets: Path) -> None:
|
||||
# Explicit empty string on argv is refused (not silently stored).
|
||||
assert _run(secret_command="set", name="K", value="") == 1
|
||||
|
||||
def test_rm_missing_is_nonzero(self, file_secrets: Path) -> None:
|
||||
assert _run(secret_command="rm", name="ABSENT", yes=True) == 1
|
||||
|
||||
def test_no_subcommand_usage(self, file_secrets: Path, capsys: object) -> None:
|
||||
assert _run(secret_command=None) == 1
|
||||
assert "Usage" in capsys.readouterr().out # type: ignore[attr-defined]
|
||||
Reference in New Issue
Block a user