yera.creds.policy

Policy operations for controlled secret access.

Symbols

def require_authorized_credential_group — Return a group's stable owner ID after project authorization.
def resolve_authorized_tool_secrets — Authorize a project and resolve its declared ordinary credentials.
def resolve_tool_secrets — Resolve declared ordinary credentials for one authorized tool group.

require_authorized_credential_group

require_authorized_credential_group(
    groups: Mapping[str, CredentialGroupRecord],
    group_name: str,
    project_root: Path,
) → str

Return a group's stable owner ID after project authorization.

Parameters

groups
type: Mapping[str, CredentialGroupRecord]

Credential groups keyed by mutable display name.

group_name
type: str

Configured credential-group name.

project_root
type: Path

Project requesting access.

Returns

type: str

Stable owner ID used to resolve the group's ordinary secrets.

Raises

CredentialGroupNotFoundError

If the named group does not exist.

SecretAccessDeniedError

If the project is not authorized.

resolve_authorized_tool_secrets

resolve_authorized_tool_secrets(
    store: SecretStore,
    groups: Mapping[str, CredentialGroupRecord],
    group_name: str,
    project_root: Path,
    names: list[str],
) → dict[str, SecretValue]

Authorize a project and resolve its declared ordinary credentials.

Parameters

store
type: SecretStore

Secret backend containing opaque values.

groups
type: Mapping[str, CredentialGroupRecord]

Credential groups keyed by mutable display name.

group_name
type: str

Configured credential-group name.

project_root
type: Path

Project requesting access.

names
type: list[str]

Exact names or explicit .* namespaces declared by the tool.

Returns

type: dict[str, SecretValue]

Requested ordinary credential values keyed by name.

Raises

CredentialGroupNotFoundError

If the named group does not exist.

SecretAccessDeniedError

If the project is not authorized.

SecretNotFoundError

If a declared credential is absent.

resolve_tool_secrets

resolve_tool_secrets(
    store: SecretStore,
    owner_id: str,
    names: list[str],
) → dict[str, SecretValue]

Resolve declared ordinary credentials for one authorized tool group.

Parameters

store
type: SecretStore

Secret backend containing opaque values.

owner_id
type: str

Stable identity of the authorized credential group.

names
type: list[str]

Exact credential names declared by the tool.

Returns

type: dict[str, SecretValue]

Requested values keyed by their declared names.

Raises

SecretNotFoundError

If any declared ordinary credential is absent.