Add agentvault with a seed-outpost subcommand
Interactive agents are classifier-blocked from plumbing credentials through a shell, so seeding an Authentik outpost token into Vault KV needs to happen inside one binary invocation that never exposes the secret. - Add cmd/agentvault, a fourth CLI sharing the agentpr Vault AppRole login (role_id only, VAULT_ADDR/AGENT_APPROLE_ROLE_ID defaults unchanged). - Add `agentvault seed-outpost`: read the Authentik API token from kv/service/authentik/agent-api-token (field `token`, falling back to `api_token`), exact-match the outpost by name via the instances search, fetch its key from /api/v3/core/tokens/<identifier>/view_key/ and write it to --dest-path under --dest-key. - Print only the outpost name, token identifier, dest path and new KV version; keep secret material out of results, errors and logs. - Distinguish the failure stages (login, KV read denied, outpost missing, view_key, KV write denied) with ErrVaultDenied/ErrVaultNotFound/ ErrOutpostNotFound sentinels and actionable messages. - Add internal/agent vaultkv.go (AppRole-authenticated KV-v2 client) and authentik.go (outpost search + view_key) for reuse by future flows. - Cover the happy path, idempotent re-run, field fallback and every failure mode with httptest servers, including a leak check on error strings. - Wire agentvault into the Makefile, build-rpm.sh, nfpm contents, release cross-builds/assets, README and AGENTS.md.
This commit is contained in:
@@ -10,6 +10,8 @@ happens to run the command.
|
||||
acting on.
|
||||
- **`agentws`** — manage per-branch git worktrees for `unkin-agent`, cloning
|
||||
into Ben's source checkout and isolating agent work under the XDG cache.
|
||||
- **`agentvault`** — run deterministic Vault flows in one invocation, so agents
|
||||
never plumb secret material through a shell.
|
||||
|
||||
## How it gets a token
|
||||
|
||||
@@ -28,6 +30,7 @@ Everything is configured by environment variables, all with defaults:
|
||||
| `AGENTWS_SRC_ROOT` | `~/src/prodenv` | source-of-truth checkout root (`agentws`) |
|
||||
| `AGENTWS_ROOT` | `~/.cache/agentws` | worktree root (`agentws`) |
|
||||
| `AGENTWS_OWNER` | `unkin` | Gitea org that owns the repos (`agentws`) |
|
||||
| `AUTHENTIK_URL` | `https://identity.k8s.syd1.au.unkin.net` | Authentik base URL (`agentvault`) |
|
||||
|
||||
## agentpr
|
||||
|
||||
@@ -121,10 +124,45 @@ the **per-worktree** config. Clone/fetch use the same helper via a transient
|
||||
removal `agentws` fetches in `~/src/prodenv/<repo>` so its default branch stays
|
||||
current.
|
||||
|
||||
## agentvault
|
||||
|
||||
Deterministic Vault flows, each a single self-contained invocation: the tool
|
||||
reads and writes the secrets itself, and prints only identifiers.
|
||||
|
||||
### seed-outpost
|
||||
|
||||
Copy an Authentik outpost's token into Vault KV-v2. `agentvault` reads the
|
||||
Authentik API token from `kv/service/authentik/agent-api-token`, resolves the
|
||||
named outpost's `token_identifier`, fetches its key via
|
||||
`/api/v3/core/tokens/<identifier>/view_key/` and writes it to the destination
|
||||
KV path. The token value is never printed or logged.
|
||||
|
||||
```bash
|
||||
agentvault seed-outpost \
|
||||
--outpost k8s-outpost \
|
||||
--dest-path kubernetes/namespace/authentik/default/outpost-token
|
||||
```
|
||||
|
||||
```
|
||||
outpost: k8s-outpost
|
||||
token_identifier: ak-outpost-k8s-outpost
|
||||
dest: kv/kubernetes/namespace/authentik/default/outpost-token
|
||||
version: 3
|
||||
```
|
||||
|
||||
Re-running is safe: it writes a new KV version. Flags: `--outpost` and
|
||||
`--dest-path` are required; `--dest-key` (default `token`), `--kv-mount`
|
||||
(default `kv`), `--token-path` (default `service/authentik/agent-api-token`) and
|
||||
`--authentik-url` override the rest.
|
||||
|
||||
Errors name the failing stage: AppRole login, KV read denied (policy not
|
||||
applied), outpost not found (terraform not applied), `view_key` failure, or KV
|
||||
write denied.
|
||||
|
||||
## Build & package
|
||||
|
||||
```bash
|
||||
make build # -> dist/agentpr, dist/watchpr, dist/agentws
|
||||
make build # -> dist/agentpr, dist/watchpr, dist/agentws, dist/agentvault
|
||||
make test # go test -race ./...
|
||||
make rpm # build + package dist/agent-tools-<version>-1.x86_64.rpm
|
||||
```
|
||||
|
||||
Reference in New Issue
Block a user