hcp-vault-secrets-wrapper
Simple HCP Vault Secrets Wrapper library
Approach
- Simple HTTP client implementation in generic python
Required Variables
- Client ID and Client Secret: each application requires a unique client ID and secret. Keep these values secret.
- Client Org, App and Project IDs, which can be fetched from the secrets fetching URL provided by HCP:
- Example:
https://api.cloud.hashicorp.com/secrets/2023-11-28/organizations/XXXX/projects/YYYY/apps/ZZZZ/secrets:open- XXXX is the organization ID (a UUID)
- YYYY is the project ID (also a UUID)
- ZZZZ is the application ID (should be human-readble)
- Example:
Implementation
- Use the following pattern to setup an HCP Vault connection for an application
# Keep Secret
HCP_CLIENT_ID = getenv("HCP_CLIENT_ID") or None
HCP_CLIENT_SECRET = getenv("HCP_CLIENT_SECRET") or None
# Not Secret - get from HCP Vault app screen:
HCP_ORG_ID = getenv("HCP_ORG_ID") or None
HCP_PROJECT_ID = getenv("HCP_PROJECT_ID") or None
HCP_APP_ID = getenv("HCP_APP_ID") or None
# Setup secrets manage setup
secrets_mgr = HCPVaultClient(HCP_CLIENT_ID, HCP_CLIENT_SECRET, HCP_ORG_ID, HCP_PROJECT_ID, HCP_APP_ID)
# Fetch secrets
secrets_data = secrets_mgr.fetch_secrets() # Returns object with secrets from HCP
# Access static secrets:
some_secret = secrets_data["SOME_SECRET"]
# Access dynamic secrets and set environ variable
from os import environ
environ["AWS_ACCESS_KEY_ID"] = secrets_data["SOME_SECRET_AWS"]["values"]["access_key_id"]
environ["AWS_SECRET_ACCESS_KEY"] = secrets_data["SOME_SECRET_AWS"]["values"]["secret_access_key"]
environ["AWS_SESSION_TOKEN"] = secrets_data["SOME_SECRET_AWS"]["values"]["session_token"]
Refresh secrets
- The code contains two class variables that cache the secrets to avoid over-querying of secrets from HCP.
- By default, secrets are cached for 25 minutes (or can be controlled by the
refresh_timeout_minconstructor variable)
- By default, secrets are cached for 25 minutes (or can be controlled by the
- Call
fetch_secretsto either pull new secrets (if we exceed the refresh timeout) OR return the last cached secrets.
Metadata
Release files for hcp-vault-secrets-wrapper 0.7.5
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| hcp_vault_secrets_wrapper-0.7.5.tar.gz | 25.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| hcp_vault_secrets_wrapper-0.7.5-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 29.5 kB
Release files / hcp_vault_secrets_wrapper-0.7.5.tar.gz
| Download URL | hcp_vault_secrets_wrapper-0.7.5.tar.gz |
|---|---|
| Size | 25.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
22d3aa8654c7d56a7e33b92b0f4061880a5dce2a429d4685a7e824428c08f99c
|
|
BLAKE2b-256 checksum How to use checksums |
bda5496d46e1c4057d7a0b80257fb76c8087af8157a9bbc54070c06a91eb75c3
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/5.1.1 CPython/3.12.7
|
Release files / hcp_vault_secrets_wrapper-0.7.5-py3-none-any.whl
| Download URL | hcp_vault_secrets_wrapper-0.7.5-py3-none-any.whl |
|---|---|
| Size | 4.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
b52e9bcf08ef268f0bd4416769116adb3fa071925da112190b223f8c5c021ac9
|
|
BLAKE2b-256 checksum How to use checksums |
de3f61e4a36324311afb200a98aea87b2fa5eec808b2199773ccf5ba395a8274
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/5.1.1 CPython/3.12.7
|