yera.creds.store
Secret storage contracts and durable identities.
Symbols
CredentialGroupInfo
Non-sensitive information about one credential group.
Attributes
Mutable user-facing group name.
Stable owner identity retained when the group is renamed.
Project roots authorized to use the group.
CredentialStoreBackend
SecretStoreProtectedFileSecretStoreStorage boundary for credential groups and their opaque secrets.
Methods
CredentialStoreBackend.create_credential_group
create_credential_group(
name: str,
authorised_roots: list[str],
) → CredentialGroupInfoCreate and persist a credential group.
Parameters
User-facing credential-group name.
Project roots initially authorized for the group.
Returns
Non-sensitive metadata for the created group.
CredentialStoreBackend.get_credential_group
get_credential_group(
name: str,
) → CredentialGroupInfoReturn one credential group's metadata.
Parameters
User-facing credential-group name.
Returns
Non-sensitive metadata for the requested group.
CredentialStoreBackend.list_credential_groups
list_credential_groups() → tuple[CredentialGroupInfo, ...]List credential groups without exposing secret values.
Returns
Credential-group metadata ordered by name.
CredentialStoreBackend.rename_credential_group
rename_credential_group(
old_name: str,
new_name: str,
) → CredentialGroupInfoRename a credential group without changing its stable identity.
Parameters
Existing user-facing group name.
Replacement user-facing group name.
Returns
Metadata for the renamed group.
CredentialStoreBackend.delete_credential_group
delete_credential_group(
name: str,
) → intDelete a credential group and its owned secrets.
Parameters
User-facing credential-group name.
Returns
Number of associated secrets deleted.
CredentialStoreBackend.authorise_credential_group
authorise_credential_group(
name: str,
project_root: Path,
) → CredentialGroupInfoAuthorize a project root to use a credential group.
Parameters
User-facing credential-group name.
Project root to authorize.
Returns
Updated non-sensitive group metadata.
CredentialStoreBackend.update_secrets
update_secrets(
values: Mapping[SecretIdentity, SecretValue],
delete: Collection[SecretIdentity] = (),
) → tuple[SecretInfo, ...]Apply multiple secret writes and deletions atomically.
Parameters
Secret values to create or replace.
Secret identities to remove before applying writes.
Returns
Metadata for the created or replaced secrets.
CredentialStoreBackend.export_credential_group
export_credential_group(
name: str,
) → bytesSerialize one credential group and all its owned secrets.
Parameters
User-facing credential-group name.
Returns
A portable version-two credential-store document containing only the requested group and its secrets.
SecretIdentity
Durable identity of one stored secret.
Attributes
Secret category kept separate from other consumers.
Stable identifier of the owning group or connection.
Secret name within the owner.
Optional stable account identity.
SecretInfo
Non-sensitive information about one stored secret.
Attributes
Durable identity of the stored secret.
Time at which the secret was first stored.
Time at which the secret was last replaced.
SecretStore
ABCStorage boundary for individual opaque secrets.
Methods
SecretStore.get
get(
identity: SecretIdentity,
) → SecretValueReturn one secret value.
Parameters
Durable identity of the requested secret.
Returns
The opaque serialized secret value.
SecretStore.set
set(
identity: SecretIdentity,
value: SecretValue,
) → SecretInfoCreate or replace one secret.
Parameters
Durable identity of the secret.
Opaque serialized value to store.
Returns
Non-sensitive information about the stored secret.
SecretStore.compare_and_set
compare_and_set(
identity: SecretIdentity,
expected_updated_at: datetime | None,
value: SecretValue,
) → SecretInfoReplace one secret when its current state matches expectations.
Parameters
Durable identity of the secret.
Expected update time, or None when the
secret is expected not to exist.
Opaque serialized replacement value.
Returns
Non-sensitive information about the stored secret.
SecretStore.delete
delete(
identity: SecretIdentity,
) → NoneDelete one secret.
Parameters
Durable identity of the secret to delete.
SecretStore.exists
exists(
identity: SecretIdentity,
) → boolReturn whether one secret exists.
Parameters
Durable identity to test.
Returns
Whether the secret exists.
SecretStore.list_info
list_info(
namespace: str | None = None,
owner_id: str | None = None,
) → tuple[SecretInfo, ...]List non-sensitive information about matching secrets.
Parameters
Optional namespace filter.
Optional owning identifier filter.
Returns
Matching secret information without values.
SecretStoreCapabilities
Security and lifecycle capabilities exposed by a secret backend.
Attributes
Whether the backend restricts stored data from unrelated local users.
Whether secret values are encrypted while persisted.
Whether the backend requires an unlock operation.
Whether mutations replace values atomically.
SecretValue
Opaque serialized secret value.
Methods
SecretValue.__repr__
__repr__() → strReturn a redacted developer representation.
SecretValue.__str__
__str__() → strReturn a redacted user-facing representation.