yera cred

Manage credential groups and secrets.

yera cred put

Set a single credential leaf.

text
Args:
    key: Exact dotted leaf key.
    value: Credential value. Omit for interactive prompt or stdin.

Raises:
    CredentialKeyError: If the key conflicts with existing credentials or
        the supplied value is empty.
yera cred put KEY [VALUE]

Arguments

KEY
type: str (required)

Exact dotted leaf key.

VALUE
type: str = None

Credential value. Omit for interactive prompt or stdin.

yera cred get

Print the plain value of a single credential leaf.

text
Args:
    key: Exact dotted leaf key.
    allow_missing: Exit successfully without output if the key is absent.

Raises:
    CredentialKeyError: If the key identifies a namespace or is absent.
yera cred get KEY [--allow-missing]

Arguments

KEY
type: str (required)

Exact dotted leaf key.

Options

--allow-missing
type: bool = False

Exit successfully without output if the key is absent.

yera cred list

Inspect credentials for the active credential group.

text
Args:
    path: Optional dotted namespace used to scope the output.
    keys_only: Print credential names without values.
    reveal: Print decoded values instead of redacted placeholders.

Raises:
    CredentialKeyError: If incompatible output flags are combined or the
        path identifies only a single credential leaf.
yera cred list [PATH] [--keys-only] [--reveal]

Arguments

PATH
type: str = None

Optional dotted namespace used to scope the output.

Options

--keys-only
type: bool = False

Print credential names without values.

--reveal
type: bool = False

Print decoded values instead of redacted placeholders.

yera cred delete

Delete one credential leaf.

text
Args:
    key: Exact dotted credential name.

Raises:
    CredentialKeyError: If the name is absent or identifies a namespace.
yera cred delete KEY

Arguments

KEY
type: str (required)

Exact dotted credential name.

yera cred patch

Merge credential leaves into a namespace.

text
Args:
    path: Dotted namespace to merge into.
    json_str: Inline JSON object to merge.
    from_file: JSON file path, or ``-`` for standard input.

Raises:
    CredentialKeyError: If input is empty or conflicts with stored leaves.
yera cred patch PATH [JSON_STR] [--from-file STR]

Arguments

PATH
type: str (required)

Dotted namespace to merge into.

JSON_STR
type: str = None

Inline JSON object to merge.

Options

--from-file
type: str = None

JSON file path, or - for standard input.

yera cred replace

Replace all credential leaves beneath a namespace.

text
Args:
    path: Dotted namespace to replace.
    json_str: Inline JSON object to store.
    from_file: JSON file path, or ``-`` for standard input.

Raises:
    CredentialKeyError: If input is empty or conflicts with stored leaves.
yera cred replace PATH [JSON_STR] [--from-file STR]

Arguments

PATH
type: str (required)

Dotted namespace to replace.

JSON_STR
type: str = None

Inline JSON object to store.

Options

--from-file
type: str = None

JSON file path, or - for standard input.

yera cred clear

Delete credential leaves beneath an optional namespace.

text
Args:
    path: Optional dotted namespace to clear.
    force: Whether destructive bulk deletion is permitted.

Raises:
    YeraError: If force is not enabled.
    CredentialKeyError: If the path identifies only one credential leaf.
yera cred clear [PATH] [--force]

Arguments

PATH
type: str = None

Optional dotted namespace to clear.

Options

--force
type: bool = False

Whether destructive bulk deletion is permitted.

yera cred list-groups

List all credential groups with credential counts and authorised roots.

yera cred list-groups

yera cred use-group

Set [tool.yera.overrides] cred-group in pyproject.toml.

text
Non-interactive: does not touch credentials.json or authorised_roots.

Args:
    name: Credential group name to write under ``[tool.yera.overrides]``.
yera cred use-group NAME

Arguments

NAME
type: str (required)

Credential group name to write under [tool.yera.overrides].

yera cred get-group

Show active credential group or inspect a named group's metadata.

text
Args:
    name: Credential group name to inspect. If omitted, prints the active
        group name. If provided, prints the named group's metadata as JSON.
yera cred get-group [NAME]

Arguments

NAME
type: str = None

Credential group name to inspect. If omitted, prints the active group name. If provided, prints the named group's metadata as JSON.

yera cred allow-group

Add the current project root to a credential group's authorised roots.

text
Args:
    name: Credential group name to authorise for this project root.
yera cred allow-group NAME

Arguments

NAME
type: str (required)

Credential group name to authorise for this project root.

yera cred rename-group

Atomically rename a credential group in credentials.json.

text
Args:
    old_name: Existing credential group name.
    new_name: New credential group name. Must pass name validation.
yera cred rename-group OLD_NAME NEW_NAME

Arguments

OLD_NAME
type: str (required)

Existing credential group name.

NEW_NAME
type: str (required)

New credential group name. Must pass name validation.

yera cred delete-group

Delete a credential group and all its credentials from credentials.json.

text
Args:
    name: Credential group name to delete.
    force: Must be true; the command refuses to delete without ``--force``.
yera cred delete-group NAME [--force]

Arguments

NAME
type: str (required)

Credential group name to delete.

Options

--force
type: bool = False

Must be true; the command refuses to delete without --force.

yera cred export-group

Export a credential group as a portable protected-store document.

text
Args:
    name: Credential group name to export.
    output_file: Path to write the exported JSON. Uses atomic writing with
        restricted permissions on POSIX. Omit to write to standard output.
yera cred export-group NAME [--output-file PATH]

Arguments

NAME
type: str (required)

Credential group name to export.

Options

--output-file
type: Path = None

Path to write the exported JSON. Uses atomic writing with restricted permissions on POSIX. Omit to write to standard output.