cf4094b9e468507ca147c7f6c723f3b87a3fd2c8
ci / vet (pull_request) Successful in 1m9s
Vault access tokens expire (~10min); consumers hit 401s after container recreates. Now: refresh_token persisted at login and rotated on every refresh (Vaultwarden semantics); 401 on an authed call refreshes once and retries; if refresh is unavailable, full relogin (password+TOTP injected by the sm shims from the TSGCOO vault-account env) is attempted before failing. cmdLogin passes the TOTP seed again (regression). QA: corrupted access_token -> TSGCOO sm read self-healed end-to-end. Ticket: https://projects.knownelement.com/issues/832
KNELSecretsManager
Fleet secrets management: a pure-Go Bitwarden/Vaultwarden CLI (smcli)
in a house container, backed by the self-hosted TSGCOO vault. No upstream
Rust bw binary, no Node runtime, no .creds text files — those patterns
are retired (ADR-003; founder rulings #829/#832).
- Docs: docs/architecture.md (diagrams, crypto, rotation program)
- KNELBMS integration: docs/integration-knelbms.md
- Redmine: https://projects.knownelement.com/issues/832 (build) / #829 (migration+rotation)
Quick start (lane)
# TSGCOO account (COO-area chats; docker group, no sudo)
/data2/TSGCOO/.local/bin/sm status
# reachableceo crossover
~/projects/KNEL/OAM/.tools/sm env creds/cloudron # export URI/USERNAME/PASSWORD + keys
~/projects/KNEL/OAM/.tools/sm get creds/librenms --field password
~/projects/KNEL/OAM/.tools/sm setfield creds/<item> <KEY> <newvalue> # rotation updates
Layout
| Path | What |
|---|---|
cli/cmd/smcli/ |
the Go CLI (crypto, API, commands) |
docker/Dockerfile.cli |
golang build → alpine runtime (CA certs, non-root) |
docker/compose.yaml |
always-hot service ukrrs-secretsmgr-cli (digest-pinned) |
archive/rust-bw-era/ |
retired upstream-binary wrapper scripts |
docs/ADR-003-GoCLI.md |
decision record |
Rules (binding)
- Secrets live ONLY in the TSGCOO Bitwarden vault, accessed ONLY via this
CLI (container
ukrrs-secretsmgr-cli, shims above). No textfile creds, no upstream bw CLI — anywhere. - All work product is authored by Cloudron account identities (ic-builder / ic-reviewer / manager-tsg / vptechops); the founder account (ReachableCEO) reviews and approves.
- Production-affecting rotations follow the CR gating + cross-linking house rules (GLPI CR deep link in the PR/ticket; evidence on solve).
Languages
Go
48.3%
Shell
43.7%
Makefile
7%
Dockerfile
1%