yera.creds.backends.protected_file
Protected file secret-store backend.
Symbols
ProtectedFileSecretStore
CredentialStoreBackendPersist opaque secrets in an atomically replaced protected file.
Methods
ProtectedFileSecretStore.get
get(
identity: SecretIdentity,
) → SecretValueReturn one stored secret.
Parameters
Durable identity of the requested secret.
Returns
The opaque stored value.
Raises
If the secret does not exist.
ProtectedFileSecretStore.set
set(
identity: SecretIdentity,
value: SecretValue,
) → SecretInfoCreate or replace one secret.
Parameters
Durable identity of the secret.
Opaque serialized value to store.
Returns
Non-sensitive information about the stored secret.
ProtectedFileSecretStore.compare_and_set
compare_and_set(
identity: SecretIdentity,
expected_updated_at: datetime | None,
value: SecretValue,
) → SecretInfoConditionally create or replace one secret.
Parameters
Durable identity of the secret.
Expected update time, or None when absent.
Opaque serialized replacement value.
Returns
Non-sensitive information about the stored secret.
Raises
If current state differs from the expectation.
ProtectedFileSecretStore.delete
delete(
identity: SecretIdentity,
) → NoneDelete one secret.
Parameters
Durable identity of the secret.
Raises
If the secret does not exist.
ProtectedFileSecretStore.exists
exists(
identity: SecretIdentity,
) → boolReturn whether one secret exists.
Parameters
Durable identity to test.
Returns
Whether the secret exists.
ProtectedFileSecretStore.list_info
list_info(
namespace: str | None = None,
owner_id: str | None = None,
) → tuple[SecretInfo, ...]List non-sensitive information about matching secrets.
Parameters
Optional namespace filter.
Optional owning identifier filter.
Returns
Matching metadata in stable identity order.
ProtectedFileSecretStore.create_credential_group
create_credential_group(
name: str,
authorised_roots: list[str],
) → CredentialGroupInfoCreate and persist a credential group.
Parameters
User-facing credential-group name.
Project roots initially authorized for the group.
Returns
Non-sensitive metadata for the created group.
Raises
If the name is already in use.
If the name is invalid.
ProtectedFileSecretStore.list_credential_groups
list_credential_groups() → tuple[CredentialGroupInfo, ...]List credential groups without exposing secret values.
Returns
Credential-group metadata ordered by group name.
ProtectedFileSecretStore.get_credential_group
get_credential_group(
name: str,
) → CredentialGroupInfoReturn one credential group's non-sensitive metadata.
Parameters
User-facing credential-group name.
Returns
Metadata for the requested group.
Raises
If the group does not exist.
ProtectedFileSecretStore.rename_credential_group
rename_credential_group(
old_name: str,
new_name: str,
) → CredentialGroupInfoRename a credential group while retaining its stable identity.
Parameters
Existing user-facing group name.
Replacement user-facing group name.
Returns
Metadata for the renamed group.
Raises
If the source group does not exist.
If the target name is already used.
If the target name is invalid.
ProtectedFileSecretStore.delete_credential_group
delete_credential_group(
name: str,
) → intDelete a credential group and every secret it owns.
Parameters
User-facing credential-group name.
Returns
Number of associated secrets deleted with the group.
Raises
If the group does not exist.
ProtectedFileSecretStore.authorise_credential_group
authorise_credential_group(
name: str,
project_root: Path,
) → CredentialGroupInfoAuthorize a project root to use a credential group.
Parameters
User-facing credential-group name.
Project root to authorize.
Returns
Updated non-sensitive credential-group metadata.
Raises
If the group does not exist.
ProtectedFileSecretStore.update_secrets
update_secrets(
values: Mapping[SecretIdentity, SecretValue],
delete: Collection[SecretIdentity] = (),
) → tuple[SecretInfo, ...]Apply multiple secret writes and deletions atomically.
Parameters
Secret values to create or replace.
Secret identities to remove before applying writes.
Returns
Metadata for the created or replaced secrets.
ProtectedFileSecretStore.export_credential_group
export_credential_group(
name: str,
) → bytesSerialize one credential group and all its owned secrets.
Parameters
User-facing credential-group name.
Returns
A portable version-two credential-store document containing only the requested group and its secrets.
Raises
If the group does not exist.