🔐 k-bw — Sovereign Bitwarden Appliance
Zero Trust · AI-Blind · ACID Durable
The authoritative appliance for Bitwarden organization vault control. Keep AI agents and LLMs blind to your real secrets while giving them full auditing and refactoring powers.
🏛️ Project Architecture (Sovereign Tree)
BW-PROXY PROJECT
├── 📂 src/k_bw/ ◄── Core Engine (ACID Transaction, WAL, Redaction)
├── 📂 scripts/ ◄── Host-side Shims (Dynamic porting, Browser HITL)
├── 📂 docs/ ◄── Deep-dive Hardening & Operator Guides
├── 📄 install.sh ◄── System-wide Appliance Installer (Root-owned)
├── 📄 Makefile ◄── Developer & Release Automator
└── 📄 Dockerfile ◄── Multi-stage Hardened Runtime
🚀 Installation Modes
A. Appliance Mode (Standard Pro)
Ideal for production use. Installs a root-owned binary and uses the official image.
Via curl (Zero-Clone):
curl -fsSL https://raw.githubusercontent.com/kpihx-labs/k-bw/main/install.sh | sudo bash
What it does internally:
- Image: Pulls
ghcr.io/kpihx-labs/k-bw:latest. - Binary: Creates
/usr/local/bin/k-bw(owned by root). - Config: Seeds
~/.config/k-bw/(owned by the invoking user). - Data: Creates a persistent Docker volume
k-bw-data.
B. Developer Mode (Source Clone)
Ideal for contribution or source-level auditing.
git clone https://github.com/kpihx-labs/k-bw.git
cd k-bw
make docker-install # Requires SUDO for builds
⚙️ Core Mechanisms (The Magic)
1. The HITL Browser Flux
When an AI agent requests a vault change, the proxy intercepts the execution:
- Port Allocation: The host shim finds a free random port.
- Container Launch: The appliance starts, mapping the internal HITL server to that port.
- URL Interception: The shim detects the Approval URL in stdout and automatically opens your browser.
- Human Approval: You review the rationale and the diff, then approve with your Master Password.
2. The 3-Phase ACID Commit (WAL)
Every mutation is transactional.
- Simulation: Actions are validated in RAM first.
- WAL: Actions are encrypted and logged to disk before execution.
- Commit: Actions are sent to the Bitwarden CLI.
- Rollback: If a crash occurs, the proxy performs a LIFO rollback on the next start.
3. Scoped Union Fetch
To handle organizational vaults without metadata loss:
- The proxy discovers all accessible Organizations and Collections first.
- It then performs scoped queries (
--organizationid) to fetch "rich" items with full metadata. - It merges results with the global vault list, ensuring organizational assignments are preserved.
🕹️ Interface Modes
1. CLI Mode (Recommended for Humans & AI Agents) 🚀
The CLI is the most efficient and agnostic way to interact with the appliance. It uses RPC 2.0 (JSON), supports exact examples, and provides rich help documentation.
For AI Agents: Using the CLI via run_command is more token-efficient than MCP and offers greater flexibility.
k-bw admin status # Health check
k-bw admin unlock # Create a 5-minute session lease
k-bw do list-items # Quick redacted scan
[!TIP] AI Integration: To enable full AI recognition of these commands, copy the
.agents/skills/k-bwdirectory to your global~/.agents/skills/or into a project-specific.agents/skills/directory.
2. MCP Mode (Standard Stdio)
Start the stdio server for standard MCP clients like Gemini, Claude, or Cursor.
k-bw mcp serve
🛠️ Maintenance & Release
- Update:
curl ... | sudo bash(re-runs the installer). - Uninstall:
sudo ./uninstall.sh. - Release (Dev):
make release(automatic tagging and GHCR propulsion).
⚖️ License
MIT License. See LICENSE for details.
Designed with ❤️ by KpihX.
Metadata
Release files for kpihx-bw 4.0.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| kpihx_bw-4.0.0.tar.gz | 74.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| kpihx_bw-4.0.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 157.7 kB
Release files / kpihx_bw-4.0.0.tar.gz
| Download URL | kpihx_bw-4.0.0.tar.gz |
|---|---|
| Size | 74.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
12b404ed62f22173beb93d7fa9f729f4bcf930020a709a7f8a54883d54e2c800
|
|
BLAKE2b-256 checksum How to use checksums |
d5d763f68ab397bdfc60e37705076cef1e20fac65fdcb4e0ac54961c9f77b513
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.10.3 {"installer":{"name":"uv","version":"0.10.3","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"26.04","id":"resolute","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|
Release files / kpihx_bw-4.0.0-py3-none-any.whl
| Download URL | kpihx_bw-4.0.0-py3-none-any.whl |
|---|---|
| Size | 83.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
4d7a870067ec2ac1d1cc724b67ef3c39a88399655b1b67ec8889a7ac5da60e8a
|
|
BLAKE2b-256 checksum How to use checksums |
b9b9883a5a00f4ddbebf707459d508f0db7fc180b8389d40234514d144182b3b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.10.3 {"installer":{"name":"uv","version":"0.10.3","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"26.04","id":"resolute","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|