TSYS Group COO 7534964c13 fix: handle 2FA on the Bitwarden account during API login [#442]
bw login --apikey prompts for a TOTP code when 2FA is enabled on the
BW account. The previous code didn't pass one, so it would hang or
fail. Now generates a TOTP from BW_TOTP_SECRET and passes via --code.

Changes:
- BitwardenHelper.__init__ accepts totp_secret param
- login() generates a pyotp code and passes --code when secret is set
- provision-agent.py passes BW_TOTP_SECRET from environment
- docker-compose.yml and .env.example updated for the new var
- BW_PASSWORD removed from the login env (only needed for unlock via stdin)

The BW account's own TOTP secret lives in ~/.config/bw/env alongside
the other BW access info — the one exception (can't store BW's 2FA in
BW itself).

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-08-13 12:14:16 -05:00

Agent Identity Provisioning

Playwright-based automation for provisioning AI agent identities across the TSYS Group stack: Cloudron enrollment (with 2FA), SSO login, API key generation, and Bitwarden credential storage.

Overview

Each AI agent (VP TechOps, VP SecOps, etc.) gets:

  1. A dedicated Cloudron user (identity root — SSO provisions everywhere)
  2. TOTP 2FA enrolled and stored in Bitwarden
  3. API keys generated in Gitea, Discourse, Redmine (stored in Bitwarden)
  4. All credentials owned by the agent, sourced via bw-run.sh (no ~/.creds/ files)

See ~/Q3/agent-identity-bootstrap.md for the full architecture.

Usage

# 1. Create the manifest from the example
cp agents.yaml.example agents.yaml
# Edit: add Cloudron invite links for each agent

# 2. Set BW credentials
export BW_CLIENTID="..."
export BW_CLIENTSECRET="..."

# 3. Build and run
docker compose up --build

# Or run a single agent
docker compose run --rm provision --agent vp-techops

Manifest format

See agents.yaml.example. Each agent defines:

  • Cloudron invite link
  • Display name
  • Priority (Q3 vs Q4)
  • System scopes (Redmine projects, Gitea orgs, Discourse categories)
S
Description
Playwright-based automation for provisioning AI agent identities (Cloudron enrollment, SSO login, API key generation, Bitwarden storage)
Readme
274 KiB
Languages
Python 88.4%
Shell 10%
Makefile 0.9%
Dockerfile 0.7%