yera cred
Manage credential groups and secrets.
yera cred put
Set a single credential leaf.
Args:
key: Exact dotted leaf key.
value: Credential value. Omit for interactive prompt or stdin.
Raises:
CredentialKeyError: If the key conflicts with existing credentials or
the supplied value is empty.yera cred put KEY [VALUE]Arguments
Exact dotted leaf key.
Credential value. Omit for interactive prompt or stdin.
yera cred get
Print the plain value of a single credential leaf.
Args:
key: Exact dotted leaf key.
allow_missing: Exit successfully without output if the key is absent.
Raises:
CredentialKeyError: If the key identifies a namespace or is absent.yera cred get KEY [--allow-missing]Arguments
Exact dotted leaf key.
Options
Exit successfully without output if the key is absent.
yera cred list
Inspect credentials for the active credential group.
Args:
path: Optional dotted namespace used to scope the output.
keys_only: Print credential names without values.
reveal: Print decoded values instead of redacted placeholders.
Raises:
CredentialKeyError: If incompatible output flags are combined or the
path identifies only a single credential leaf.yera cred list [PATH] [--keys-only] [--reveal]Arguments
Optional dotted namespace used to scope the output.
Options
Print credential names without values.
Print decoded values instead of redacted placeholders.
yera cred delete
Delete one credential leaf.
Args:
key: Exact dotted credential name.
Raises:
CredentialKeyError: If the name is absent or identifies a namespace.yera cred delete KEYArguments
Exact dotted credential name.
yera cred patch
Merge credential leaves into a namespace.
Args:
path: Dotted namespace to merge into.
json_str: Inline JSON object to merge.
from_file: JSON file path, or ``-`` for standard input.
Raises:
CredentialKeyError: If input is empty or conflicts with stored leaves.yera cred patch PATH [JSON_STR] [--from-file STR]Arguments
Dotted namespace to merge into.
Inline JSON object to merge.
Options
JSON file path, or - for standard input.
yera cred replace
Replace all credential leaves beneath a namespace.
Args:
path: Dotted namespace to replace.
json_str: Inline JSON object to store.
from_file: JSON file path, or ``-`` for standard input.
Raises:
CredentialKeyError: If input is empty or conflicts with stored leaves.yera cred replace PATH [JSON_STR] [--from-file STR]Arguments
Dotted namespace to replace.
Inline JSON object to store.
Options
JSON file path, or - for standard input.
yera cred clear
Delete credential leaves beneath an optional namespace.
Args:
path: Optional dotted namespace to clear.
force: Whether destructive bulk deletion is permitted.
Raises:
YeraError: If force is not enabled.
CredentialKeyError: If the path identifies only one credential leaf.yera cred clear [PATH] [--force]Arguments
Optional dotted namespace to clear.
Options
Whether destructive bulk deletion is permitted.
yera cred list-groups
List all credential groups with credential counts and authorised roots.
yera cred list-groupsyera cred use-group
Set [tool.yera.overrides] cred-group in pyproject.toml.
Non-interactive: does not touch credentials.json or authorised_roots.
Args:
name: Credential group name to write under ``[tool.yera.overrides]``.yera cred use-group NAMEArguments
Credential group name to write under [tool.yera.overrides].
yera cred get-group
Show active credential group or inspect a named group's metadata.
Args:
name: Credential group name to inspect. If omitted, prints the active
group name. If provided, prints the named group's metadata as JSON.yera cred get-group [NAME]Arguments
Credential group name to inspect. If omitted, prints the active group name. If provided, prints the named group's metadata as JSON.
yera cred allow-group
Add the current project root to a credential group's authorised roots.
Args:
name: Credential group name to authorise for this project root.yera cred allow-group NAMEArguments
Credential group name to authorise for this project root.
yera cred rename-group
Atomically rename a credential group in credentials.json.
Args:
old_name: Existing credential group name.
new_name: New credential group name. Must pass name validation.yera cred rename-group OLD_NAME NEW_NAMEArguments
Existing credential group name.
New credential group name. Must pass name validation.
yera cred delete-group
Delete a credential group and all its credentials from credentials.json.
Args:
name: Credential group name to delete.
force: Must be true; the command refuses to delete without ``--force``.yera cred delete-group NAME [--force]Arguments
Credential group name to delete.
Options
Must be true; the command refuses to delete without --force.
yera cred export-group
Export a credential group as a portable protected-store document.
Args:
name: Credential group name to export.
output_file: Path to write the exported JSON. Uses atomic writing with
restricted permissions on POSIX. Omit to write to standard output.yera cred export-group NAME [--output-file PATH]Arguments
Credential group name to export.
Options
Path to write the exported JSON. Uses atomic writing with restricted permissions on POSIX. Omit to write to standard output.