edf056eb9fc4f6b4fee03325dee819ad8ad0a57f
Read-path commands over the library. Credentials never come from flags or arguments; get prints the bare value for $(...) plumbing and nothing else ever touches stdout; stderr carries only redacted diagnostics. Exit codes mirror keyproxy (0 ok, 1 usage/config, 2 auth or resolution failure). CLI tests drive the fake server through a real 0600 env file.
mopac-bitwarden-go
A 100% Go CLI for Bitwarden / Bitwarden Secrets Manager, replacing the Node
bw CLI in supply-chain-sensitive (CMMC L3/TS posture) environments. One
static binary, one auditable vendored module tree, no Node runtime.
Status: 2026-08-28 — spec seed; reference study complete, open questions pending Charles, no code yet.
Scope
- Talks to the Bitwarden Secrets Manager REST API directly with stdlib — NO official SDK (its source-available license is AGPL-incompatible).
- Machine-account auth (access-token flow) for headless/agent use; human auth flows where needed.
- Porcelain/plumbing model:
bwg get|set|list|sync ...with JSON out for scripting, plain text for humans. - Memory-only secrets handling: session token held in memory for the process lifetime and zeroed on exit; values never written to logs, disk cache, REPORT files, or crash dumps; refs logged only in redacted form.
- Pairs with ukrrs/mopac-keyproxy (placeholder keys to consumers; this CLI is how material gets INTO the vault) but fully standalone.
Non-goals
- No admin UI; a CLI and nothing else.
- Not a vault server — Vaultwarden/Bitwarden stays the store of record.
- No disk cache of secret values; no long-lived persisted sessions by default (open question 4 below may change that, founder's call).
- Not org-specific: hosts/credentials come from config and environment, never baked in.
Today vs planned
| State | |
|---|---|
| Today | Spec only (this README + LICENSE). Interim in production: the KNELSecretsManager containerized bw wrapper (ADR-002) — plain bw behind docker, plaintext env on disk, full login/unlock/sync per call. |
| Planned | Go CLI per the reference study: bw: key-ref resolution for the MOPAC harness, lookup by item name (password field), per-process unlock, never bw logout, typed not-found/unlock errors, fake-bw test stub. |
Design references
- KNELSecretsManager study — current surface, replacement design sketch, open questions (section 3 lists seven open questions for Charles: substrate, machine account, ref syntax, session lifetime, secret names, scope, subprocess injection)
- MOPAC harness DESIGN.md — Toolchain policy, 100% Go HARD RULE
- MOPAC harness DESIGN.md — Key proxy
- Parent: ukrrs/MOPAC — the harness whose
bw:key refs this unblocks
License
AGPLv3 — see LICENSE.
Languages
Go
92.8%
Shell
6.8%
Makefile
0.4%