feat(sops): @dataverket/sops, one SOPS-encrypted file per secret; fork of @zocc/sops-age #5

Merged
beddari merged 3 commits from sops-age into main 2026-09-20 17:22:47 +00:00
Owner

Three commits: the fork with two vault types, then one dropped, then the other, ending with one type named after the CLI, @dataverket/sops. One SOPS-encrypted JSON file per secret under secretsDir: put encrypts to the recipients and needs only their public keys, so a writer can store a value for readers it is not among; get decrypts one file; list walks the directory; delete removes the file. sops runs as an argument vector, values pass through a private temp dir, ageKeyFile optional so a YubiKey identity works unchanged. An existing single-file vault splits with swamp vault migrate <vault> --to-type @dataverket/sops, verified on a scratch repo. Conformance suite plus an integration test against real sops and age; quality 12/12; Apache-2.0 with NOTICE.md.

Three commits: the fork with two vault types, then one dropped, then the other, ending with one type named after the CLI, `@dataverket/sops`. One SOPS-encrypted JSON file per secret under `secretsDir`: `put` encrypts to the recipients and needs only their public keys, so a writer can store a value for readers it is not among; `get` decrypts one file; `list` walks the directory; `delete` removes the file. sops runs as an argument vector, values pass through a private temp dir, `ageKeyFile` optional so a YubiKey identity works unchanged. An existing single-file vault splits with `swamp vault migrate <vault> --to-type @dataverket/sops`, verified on a scratch repo. Conformance suite plus an integration test against real sops and age; quality 12/12; Apache-2.0 with NOTICE.md.
One-file (@dataverket/sops-age): the file @zocc/sops-age writes, changed
one value at a time with sops set, read with sops decrypt --extract,
listed from the plaintext key names without a key, deleted with sops
unset. Per-file (@dataverket/sops-age-files): one encrypted file per
secret, so a writer holding only the recipients' public keys can add a
value it cannot read back. sops runs as an argument vector, values reach
it on stdin or through a private temporary directory, and ageKeyFile is
optional so a YubiKey identity works unchanged. Conformance and
integration tests against real sops and age; quality 12/12. Apache-2.0
with NOTICE.md.
Nothing produces a secret for readers this repository is not among, so
the write-with-public-keys-only layout has no consumer. The one-file
type keeps the name @dataverket/sops-age. The provider stays in history
(the previous commit) should a producer appear.
beddari changed title from feat(sops-age): @dataverket/sops-age, a fork of @zocc/sops-age that changes one value at a time to feat(sops): @dataverket/sops, one SOPS-encrypted file per secret; fork of @zocc/sops-age 2026-09-20 17:21:16 +00:00
The single-file provider was the upstream layout with a better write
path; what this repository wants is the other one, so it is the sole
type and takes the extension's name, after the CLI. One SOPS-encrypted
file per secret: put needs the recipients' public keys and nothing else,
get decrypts one file, list walks the directory, delete removes the
file. An existing single-file vault splits with swamp vault migrate.
beddari deleted branch sops-age 2026-09-20 17:22:48 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dataverket/swamp-extensions!5
No description provided.