Skip to main content

Keep It Secret by BTHLabs

Keep It Secret is a small Python library for declarative management of app secrets.

Docs | Source repository

Installation

$ pip install keep_it_secret

Usage

Keep It Secret gives a developer API needed to declare secrets used by the app and access them in a secure, uniform manner.

Consider the following example:

from secrets_manager import (
    AbstractField, EnvField, LiteralField, Secrets, SecretsField,
)
from secrets_manager.ext.aws import AWSSecrets, AWSSecretsManagerField

class AppSecrets(Secrets):
    secret_key: str = AbstractField.new()
    db_password: str = EnvField.new('APP_DB_PASSWORD', required=True)
    pbkdf2_iterations_count: int = EnvField(
        'APP_PBKDF2_ITERATIONS_COUNT',
        default=16384,
        required=False,
        as_type=int,
    )

class DevelopmentSecrets(AppSecrets):
    secret_key: str = LiteralField.new('thisisntsecure')

class ProductionSecrets(AppSecrets):
    aws: AWSSecrets = SecretsField.new(AWSSecrets)
    secret_key: str = AWSSecretsManagerField(
        'app/production/secret_key', required=True,
    )
    db_password: str = AWSSecretsManagerField(
        'app/production/db_password', required=True,
    )

The AppSecrets class serves as base class for environment specific classes. The environment specific classes can overload any field, add new fields and extend the base class to provide custom behaviour.

The DevelopmentSecrets class uses environment variables and literal values to provide secrets suitable for the development environment:

>>> development_secrets = DevelopmentSecrets()
>>> development_secrets.secret_key
'thisisntsecure'
>>> development_secrets.db_password
'spam'
>>> development_secrets.pbkdf2_iterations_count
1024

The ProductionSecrets class uses environment variables and AWS Secrets Manager to provide secrets suitable for the development environment:

>>> production_secrets = ProductionSecrets()
>>> production_secrets.aws.access_key_id
'anawsaccesskey'
>>> production_secrets.secret_key
'asecuresecretkey'
>>> production_secrets.db_password
'asecuredbpassword'
>>> production_secrets.pbkdf2_iterations_count
16384

Author

Keep It Secret is developed by Tomek Wójcik.

License

Keep It Secret is licensed under the MIT License.

Release files for keep-it-secret 1.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for keep-it-secret 1.2.0
File Size Uploaded
keep_it_secret-1.2.0.tar.gz 9.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for keep-it-secret 1.2.0
File Interpreter ABI Platform
keep_it_secret-1.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 20.8 kB

Release files / keep_it_secret-1.2.0.tar.gz

Download URL keep_it_secret-1.2.0.tar.gz
Size 9.1 kB
Tags Source
SHA-256 checksum
How to use checksums
2585591d451674e30c08fcdbba95de2180904069da149bca628cc51261720839
BLAKE2b-256 checksum
How to use checksums
6d5fd7064411d8e925de9f642fbc00f34e03e4cfeb3ab366f1c696a36e4e241f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.2 CPython/3.10.13

Release files / keep_it_secret-1.2.0-py3-none-any.whl

Download URL keep_it_secret-1.2.0-py3-none-any.whl
Size 11.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
aae8f3d3c1db93223ad3afb5c35c2c7202068b082b8bf7d199ed5bc610e63449
BLAKE2b-256 checksum
How to use checksums
fb8a49e2df9e586a19122b5fc12ea097a0452da1ed7e0c24fc254ba726839f92
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.2 CPython/3.10.13

Release history Release notifications | RSS feed

This release

1.2.0 This release

2 release files

1.1.0

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page