Keeper Secrets Manager Storage
The Keeper Secrets Manager Storage module for working with custom key-value storages, creating and managing configuration files. To be used with keeper-secrets-manager-core.
For more information see our official documentation page https://docs.keeper.io/secrets-manager/secrets-manager
Change Log
1.1.0
- Raised minimum Python version to 3.9.2. Python 3.9.0 and 3.9.1 are excluded by the transitive
cryptography>=46.0.5constraint pulled in viakeeper-secrets-manager-core>=17.2.0. Users on Python 3.6 – 3.8 should pin tokeeper-secrets-manager-storage<1.1.0; pip will auto-route them. - Updated minimum
keeper-secrets-manager-coredependency to 17.2.0 - Added
threading.RLockto all backends — prevents data corruption under concurrent use - Replaced MD5 with SHA-256 for change-detection hashing; fixed Azure AES-GCM nonce from 16 to 12 bytes (NIST SP 800-38D)
- Encrypt/decrypt failures now raise instead of silently corrupting storage state
delete_all()removes the backing config file instead of writing an empty encrypted blob__save_configwrites to disk before updating in-memory state — prevents divergence on write failuredecrypt_config()default changed fromautosave=Truetoautosave=False— stray calls no longer overwrite the encrypted file with plaintext__load_configcheck fixed fromif config:toif config is not None:— a plaintext{}config is now correctly re-encrypted on first load_get_instance_regionandread_config(AWS Secrets Manager provider) now raise on failure instead of silently returning empty valuesAwsSecretStorage.__init__now eagerly loads the config on construction, matching all other backendsAwsSecretStorage.__load_config()now raises when the underlying AWS Secrets Manager call fails — previously the exception fromread_configwas logged but not propagated, leavingconfig = {}with no error- Non-UTF8 bytes that are not a valid encrypted blob now raise a clear
"is not a valid encrypted config file"exception across all encrypted backends (nfast, AWS KMS, Azure KeyVault) - HsmNfast and AwsKms now raise
"is not a valid encrypted config file"when decryption produces empty output — previously HsmNfast leaked a bareJSONDecodeErrorand AwsKms logged silently without raising, unlike Azure __save_configandcreate_config_file_if_missingnow use atomic writes (write to<path>.tmp, thenos.replace) across all three encrypted file backends (Azure KeyVault, AWS KMS, HsmNfast) — a write failure no longer truncates the existing config to 0 bytes
1.0.2
- Reverted mandatory boto3 dependency; boto3 remains optional via lazy import
1.0.1
- Added new storage type storage type for AWS Secrets Manager
1.0.0
- Initial release
Metadata
Release files for keeper-secrets-manager-storage 1.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| keeper_secrets_manager_storage-1.1.0.tar.gz | 27.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| keeper_secrets_manager_storage-1.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 48.3 kB
Release files / keeper_secrets_manager_storage-1.1.0.tar.gz
| Download URL | keeper_secrets_manager_storage-1.1.0.tar.gz |
|---|---|
| Size | 27.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
60528c43b3ec18abae2b4a1a06258e1ebd4003dbf1af7a77e0a73234a24f9de0
|
|
BLAKE2b-256 checksum How to use checksums |
14bc94be34dc4297cfd60f78c27e64d41ef36fff9dba74989c4eb742808d7772
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 1, 2026.
Transparency logRelease files / keeper_secrets_manager_storage-1.1.0-py3-none-any.whl
| Download URL | keeper_secrets_manager_storage-1.1.0-py3-none-any.whl |
|---|---|
| Size | 21.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
655af4569665d9cd0ed658f1684a9355d70adf03ac5b93495e40da8f9f9249b7
|
|
BLAKE2b-256 checksum How to use checksums |
4ceb244018d968d61a4ca2e9cb4f28126a5416913fc9082c213d9e403c708ec5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.13
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 1, 2026.
Transparency log