Teller: Universal secret manager, never leave your terminal to use secrets
github.com
github.com
export secret=$(pass secret/foo)
I'm asked for my GPG password once when I enter the project dir, and when I exit the project dir it's cleared from my environment. Pretty decent and cheap solution.Which is gpg based and extremely scriptable. You can pipe it into your platforms virtual/emualted keyboard like xdotool on linux to get "universal" integration.
That said, your solution is cool. It makes me want to find a reason to use it!
As a consultant, simple solutions that allow for quickly (manual) setting and getting rid of environments when done have worked best over the years. Using dedicated windows and desktops helps your brain to use "physical" location to keep you from messing things up. Obviously your mileage may vary if you mostly work on just one project at a time.
Finally decided to try out pass, it's pretty slick and makes a lot of sense:
$ pass init 1234ABCDEBEEF # create password store using GPG key ID
$ pass git init
$ pass git remote add origin https://github.com/foo/bar.git
$ pass generate A_Folder/An_ID 22
/Users/itsme/.password-store/A_Folder
[main 1959acb] Add generated password for A_Folder/An_ID.
1 file changed, 0 insertions(+), 0 deletions(-)
create mode 100644 A_Folder/An_ID.gpg
The generated password for A_Folder/An_ID is:
|tfj!eU8e/r%DF|2@fJ`ZH
$ pass git push -u --all
$ pass ls
Password Store
└── A_Folder
└── An_IDIt could also be both.
I've got something of a wrapper script at https://github.com/bbkane/dotfiles/blob/8573e44d0f9fb5ddcbdc...
Its getting a bit too unwieldy to stay as a single Python file and add tests and features, so I'm rewriting it in Go (nothing useful yet though)
Create a DB in MacOS keychain called envs:
security create-keychain -P envs
Then use these shell functions: which get-env
get-env () {
security find-generic-password -s "$1" -w envs
}
which add-env
add-env () {
security add-generic-password -a "$USER" -s "$1" -w "$2" envs
}
Then add one via: add-env ENVNAME SECRET
Example using it: ENVVAR=“$(get-env ENVNAME)” ./script.sh