Read-path commands over the library. Credentials never come from flags
or arguments; get prints the bare value for $(...) plumbing and nothing
else ever touches stdout; stderr carries only redacted diagnostics. Exit
codes mirror keyproxy (0 ok, 1 usage/config, 2 auth or resolution
failure). CLI tests drive the fake server through a real 0600 env file.
Credentials arrive only from BW_* process env or an env file parsed in
pure Go (never sourced, never exec'd); files looser than 0600 are refused
before a single byte is read, and errors carry line numbers and key
names, never values. Env wins over file, per the porting-notes
precedence.
Public surface Authenticate/GetSecret/ListSecrets/ListProjects: OAuth
client_credentials against /identity/connect/token (with the
encrypted_payload organization-key unwrap), refresh-before-expiry, and
bearer reads under /api with in-memory decryption. Errors are fixed
reason enums that can never embed material. Everything is tested against
an in-process fake Secrets Manager speaking the same protocol and crypto
(auth failure, expiry, refresh, missing secrets, malformed payloads,
tampered MACs, plaintext mode, and redaction sweeps over every error
path); the real vault is never contacted.