Skip to main content

Keeper Secrets Manager Storage

The Keeper Secrets Manager Storage module for working with custom key-value storages, creating and managing configuration files. To be used with keeper-secrets-manager-core.

For more information see our official documentation page https://docs.keeper.io/secrets-manager/secrets-manager

Change Log

1.1.0

  • Raised minimum Python version to 3.9.2. Python 3.9.0 and 3.9.1 are excluded by the transitive cryptography>=46.0.5 constraint pulled in via keeper-secrets-manager-core>=17.2.0. Users on Python 3.6 – 3.8 should pin to keeper-secrets-manager-storage<1.1.0; pip will auto-route them.
  • Updated minimum keeper-secrets-manager-core dependency to 17.2.0
  • Added threading.RLock to all backends — prevents data corruption under concurrent use
  • Replaced MD5 with SHA-256 for change-detection hashing; fixed Azure AES-GCM nonce from 16 to 12 bytes (NIST SP 800-38D)
  • Encrypt/decrypt failures now raise instead of silently corrupting storage state
  • delete_all() removes the backing config file instead of writing an empty encrypted blob
  • __save_config writes to disk before updating in-memory state — prevents divergence on write failure
  • decrypt_config() default changed from autosave=True to autosave=False — stray calls no longer overwrite the encrypted file with plaintext
  • __load_config check fixed from if config: to if config is not None: — a plaintext {} config is now correctly re-encrypted on first load
  • _get_instance_region and read_config (AWS Secrets Manager provider) now raise on failure instead of silently returning empty values
  • AwsSecretStorage.__init__ now eagerly loads the config on construction, matching all other backends
  • AwsSecretStorage.__load_config() now raises when the underlying AWS Secrets Manager call fails — previously the exception from read_config was logged but not propagated, leaving config = {} with no error
  • Non-UTF8 bytes that are not a valid encrypted blob now raise a clear "is not a valid encrypted config file" exception across all encrypted backends (nfast, AWS KMS, Azure KeyVault)
  • HsmNfast and AwsKms now raise "is not a valid encrypted config file" when decryption produces empty output — previously HsmNfast leaked a bare JSONDecodeError and AwsKms logged silently without raising, unlike Azure
  • __save_config and create_config_file_if_missing now use atomic writes (write to <path>.tmp, then os.replace) across all three encrypted file backends (Azure KeyVault, AWS KMS, HsmNfast) — a write failure no longer truncates the existing config to 0 bytes

1.0.2

  • Reverted mandatory boto3 dependency; boto3 remains optional via lazy import

1.0.1

  • Added new storage type storage type for AWS Secrets Manager

1.0.0

  • Initial release

Metadata

Release files for keeper-secrets-manager-storage 1.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for keeper-secrets-manager-storage 1.1.0
File Size Uploaded
keeper_secrets_manager_storage-1.1.0.tar.gz 27.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for keeper-secrets-manager-storage 1.1.0
File Interpreter ABI Platform
keeper_secrets_manager_storage-1.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 48.3 kB

Release files / keeper_secrets_manager_storage-1.1.0.tar.gz

Download URL keeper_secrets_manager_storage-1.1.0.tar.gz
Size 27.3 kB
Tags Source
SHA-256 checksum
How to use checksums
60528c43b3ec18abae2b4a1a06258e1ebd4003dbf1af7a77e0a73234a24f9de0
BLAKE2b-256 checksum
How to use checksums
14bc94be34dc4297cfd60f78c27e64d41ef36fff9dba74989c4eb742808d7772
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 1, 2026.

Transparency log

Release files / keeper_secrets_manager_storage-1.1.0-py3-none-any.whl

Download URL keeper_secrets_manager_storage-1.1.0-py3-none-any.whl
Size 21.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
655af4569665d9cd0ed658f1684a9355d70adf03ac5b93495e40da8f9f9249b7
BLAKE2b-256 checksum
How to use checksums
4ceb244018d968d61a4ca2e9cb4f28126a5416913fc9082c213d9e403c708ec5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.13

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jun 1, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.1.0 This release

2 release files

1.0.2

1 release file

1.0.1

1 release file

1.0.0

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page