axm-doctor
Env bootstrap + auth-status doctor (detect, propose, orchestrate)
Overview
Env bootstrap + auth-status doctor (detect, propose, orchestrate)
Features
- ✅ Bootstrap-safe detection — importing
axm_doctor(oraxm_doctor.detect) pulls no AXM package:detect.pydefers its AXM imports and the package re-exports lazily (PEP 562).detect_toolremains a stdlib + pydantic probe. On eachdetect_authcall, the credential catalog is discovered lazily; if it is unavailable, detection safely degrades to binary presence. - ✅ Config-resolvability checks —
detect_git_identityreports whether a git committer identity is resolvable (a truthy[git].defaultin the axm-config store, else the exit code ofgit config --get user.email) anddetect_gh_configreports whetherghcarries a base config (gh config get git_protocolexit code;not_installedwhenghis absent). Value-free like auth: only the store presence and exit codes are inspected, never the identity/config value. Both degrade tounconfiguredon any error instead of raising. Theenv_doctortool surfaces them under aconfigkey ({git: {state}, gh: {state}}). - ✅ Declaration-driven, read-only auth — each package that drives a third-party tool declares how to probe it and owns every tool-specific path, service name and recovery command.
detect_authonly translates the declaration outcomes intologged_in,logged_outornot_installed; it never reads or returns authentication material.AuthStatus.declaration_consultedisTruewhen such a declaration was found and consulted, including when its probe could not conclude. Without a declaration, the flag isFalse: an installed binary yieldsundeterminedbecause its session cannot be verified, while an absent binary yieldsnot_installed. - ✅ Frozen result models —
ToolStatus,AuthStatus,GitIdentityStatusandGhConfigStatusare immutable pydantic models; authentication results contain state metadata, never a token. - ✅ Install plans, never silent installs —
install_commandproposes the official install command for a known tool (uv,claude,codex) without running anything;run_installis a dry-run by default (confirm=False) that only echoes the command it would run. It installs strictly when the caller opts in withconfirm=True, then re-detects the tool viadetect_tool. - ✅ Kind-aware, value-free provenance —
collect_credential_provenancereports each declaration with its coordinate, declaredkind, serving layer/state, and presence flag. Credential kinds (for exampletoken) andauth_dependencycoexist in one report; a failing declaration is isolated asunknown/ absent without erasing healthy peer verdicts. - ✅ Orchestrates, never possesses —
missing_secretsreads the axm-vault catalog and value-free resolver provenance to list credential specs that resolve tomissing;auth_dependencydeclarations are excluded because an OAuth/session dependency is not a secret to provision. AMissingSecretcan identify the account concerned withinstanceor signal that a multi-instance group declares no account yet withawaiting_instance; account lookups use only axm-vault's exact canonical coordinate, so a served sibling cannot hide a starving account.provision_missingis a dry-run by default (confirm=False) that returns only credential groups it would prompt for; onconfirm=Trueit delegates to vault'srun_setup(only=…). The secret value never transits axm-doctor — every write goes through vault's API.
from axm_doctor import detect_tool, detect_auth
from axm_doctor.detect import detect_git_identity, detect_gh_config
detect_tool("uv") # ToolStatus(name='uv', state='present', version='0.5.1', path=...)
detect_auth("gh") # declaration -> AuthStatus(state='logged_in', declaration_consulted=True, ...)
detect_auth("unknown") # PATH fallback -> AuthStatus(..., declaration_consulted=False)
detect_git_identity() # GitIdentityStatus(state='configured') — store [git].default or `git config user.email`
detect_gh_config() # GhConfigStatus(state='configured') — `gh config get git_protocol`
from axm_doctor import install_command, run_install
plan = install_command("uv") # InstallPlan(tool='uv', human_command='curl -LsSf https://astral.sh/uv/install.sh | sh', ...)
install_command("bogus") # None — never guesses a command
run_install(plan) # dry-run (confirm=False): executed=False, nothing installed, command echoed
run_install(plan, confirm=True) # installs, then re-detects: InstallResult(executed=True, returncode=0, post_check=ToolStatus(...))
from axm_doctor import missing_secrets, provision_missing
missing_secrets() # MissingSecret rows; instance identifies the account when known
# awaiting_instance=True means a multi group declares no account yet
# [] when the vault catalog is empty — never reads a secret value
provision_missing() # dry-run (confirm=False): ProvisionResult(provisioned=False, groups=['research.fred']) — the groups it WOULD prompt for
provision_missing(confirm=True) # delegates to vault's run_setup(only=...); doctor never stores a secret itself
# in a non-interactive shell (no TTY) it provisions nothing: ProvisionResult(provisioned=False, reason=...)
CLI
The axm-doctor console script has two commands:
axm-doctor check # read-only report (tools + auth + provenance by kind + missing credentials)
axm-doctor bootstrap # interactive repair: installs absent tools / runs vault setup only on an explicit "y"
The same read-only surface is exposed as the env_doctor and auth_status
axm.tools (MCP + axm <tool> CLI + DAG node). In the per-tool auth map,
auth_status publishes {state, login_cmd, declaration_consulted}; its text adds
[no declaration] only when no discovered declaration covered that tool. The
credential report keeps its value-free {layer, present} shape and groups
provenance by declared kind; no token value is ever serialized.
Installation
uv add axm-doctor
Or as a workspace dependency in pyproject.toml:
[project]
dependencies = ["axm-doctor"]
[tool.uv.sources]
axm-doctor = { workspace = true }
Development
This package is part of the axm-forge uv workspace.
# Run this package's tests (from the workspace root)
uv run --package axm-doctor pytest packages/axm-doctor
# Lint + type-check + tests for the whole workspace
make check
License
Apache-2.0 — © 2026 Gabriel Jarry
Metadata
Release files for axm-doctor 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| axm_doctor-0.1.0.tar.gz | 50.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| axm_doctor-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 76.8 kB
Release files / axm_doctor-0.1.0.tar.gz
| Download URL | axm_doctor-0.1.0.tar.gz |
|---|---|
| Size | 50.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
6f990fc9cc11b2a444db6de965d5b12c1bd35d08821fb38b95d19147cd1aeaf9
|
|
BLAKE2b-256 checksum How to use checksums |
dc0392346644bc6614cb63150de1bae48ccc1955e5792f2a12f7933e90648445
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 8, 2026.
Transparency logRelease files / axm_doctor-0.1.0-py3-none-any.whl
| Download URL | axm_doctor-0.1.0-py3-none-any.whl |
|---|---|
| Size | 26.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0735f87e4d1e2c07dbe3e914fdedfba5feeb210c7077f8983dc90245b96f57f1
|
|
BLAKE2b-256 checksum How to use checksums |
e40e277124424084bf240f45a1e88818605475686e8a4118ea18320808203198
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 8, 2026.
Transparency log