ic-builder b3caef6888
ci / vet (push) Successful in 1m2s
ci / diagrams (push) Successful in 3m34s
CI diagrams: install chromium + expose renderer stderr
The diagrams job ran without a browser (the earlier fix landed on a
deleted branch by mistake). Now installs Debian chromium, points
puppeteer at it, and prints mmdc stderr on failure.
Ticket: https://projects.knownelement.com/issues/832
2026-09-07 10:08:24 -05:00
2024-11-24 04:02:14 +00:00
2025-07-16 10:17:07 -05:00

KNELSecretsManager

Fleet secrets management: a pure-Go Bitwarden/Vaultwarden CLI (smcli) in a house container, backed by the self-hosted TSGCOO vault. No upstream Rust bw binary, no Node runtime, no .creds text files — those patterns are retired (ADR-003; founder rulings #829/#832).

Quick start (lane)

# TSGCOO account (COO-area chats; docker group, no sudo)
/data2/TSGCOO/.local/bin/sm status

# reachableceo crossover
~/projects/KNEL/OAM/.tools/sm env creds/cloudron   # export URI/USERNAME/PASSWORD + keys
~/projects/KNEL/OAM/.tools/sm get creds/librenms --field password
~/projects/KNEL/OAM/.tools/sm setfield creds/<item> <KEY> <newvalue>   # rotation updates

Layout

Path What
cli/cmd/smcli/ the Go CLI (crypto, API, commands)
docker/Dockerfile.cli golang build → alpine runtime (CA certs, non-root)
docker/compose.yaml always-hot service ukrrs-secretsmgr-cli (digest-pinned)
archive/rust-bw-era/ retired upstream-binary wrapper scripts
docs/ADR-003-GoCLI.md decision record

Rules (binding)

  • Secrets live ONLY in the TSGCOO Bitwarden vault, accessed ONLY via this CLI (container ukrrs-secretsmgr-cli, shims above). No textfile creds, no upstream bw CLI — anywhere.
  • All work product is authored by Cloudron account identities (ic-builder / ic-reviewer / manager-tsg / vptechops); the founder account (ReachableCEO) reviews and approves.
  • Production-affecting rotations follow the CR gating + cross-linking house rules (GLPI CR deep link in the PR/ticket; evidence on solve).
S
Description
Managing secrets at TSYS using bitwarden/envwarden/our own glue code.
Readme AGPL-3.0
24 MiB
Languages
Go 48.3%
Shell 43.7%
Makefile 7%
Dockerfile 1%