Skip to main content

secretspec (Python SDK)

Python bindings for SecretSpec, a declarative secrets manager. This package is a thin client over a pyo3 extension that calls secretspec::resolve_json directly: resolution (providers, chains, profiles, generation, as_path) happens in the Rust core, so the SDK inherits every provider with no Python-side logic.

from secretspec import SecretSpec

resolved = (
    SecretSpec.builder()
    .with_provider("keyring://")
    .with_profile("production")
    .with_reason("boot web app")
    .load()
)

print(resolved.provider, resolved.profile)
db = resolved.secrets["DATABASE_URL"]
print(db.get)              # the value, or the file path for as_path secrets
resolved.set_as_env()      # export everything into os.environ

A missing required secret raises MissingRequiredError; any other failure raises SecretSpecError (with a stable .kind).

Cleanup

as_path secrets are materialized to temp files that outlive the call. Use the result as a context manager (with SecretSpec.builder()...load() as resolved:) or call resolved.close() when done so the secret files do not accumulate.

Value-free report

report() returns the inventory/preflight view: per-secret status and provenance, never a value. Unlike load(), it does not raise when a required secret is missing — it appears as a SecretReport with status "missing_required".

report = SecretSpec.builder().with_profile("production").report()
for s in report.secrets:
    print(s.name, s.status, s.required)

Native library

The Rust resolver is statically linked into a compiled pyo3 extension (secretspec._native, built from the secretspec-py-native crate) inside the installed wheel, so there is nothing to locate at runtime. The prebuilt abi3 wheels are self-contained (pip install secretspec). From a source checkout the extension is built on demand by the test harness via maturin develop, which needs maturin and a Rust toolchain on PATH.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

secretspec-0.16.0-cp39-abi3-manylinux_2_28_x86_64.whl (15.3 MB view details)

Uploaded CPython 3.9+manylinux: glibc 2.28+ x86-64

secretspec-0.16.0-cp39-abi3-manylinux_2_28_aarch64.whl (15.0 MB view details)

Uploaded CPython 3.9+manylinux: glibc 2.28+ ARM64

secretspec-0.16.0-cp39-abi3-macosx_11_0_arm64.whl (11.4 MB view details)

Uploaded CPython 3.9+macOS 11.0+ ARM64

File details

Details for the file secretspec-0.16.0-cp39-abi3-manylinux_2_28_x86_64.whl.

File metadata

File hashes

Hashes for secretspec-0.16.0-cp39-abi3-manylinux_2_28_x86_64.whl
Algorithm Hash digest
SHA256 308c0eabb9829d2e5ce516c1db03a22d69818f9f9975ad2fff263d37962a6f4a
MD5 f342d6127f4fdaca8bfb724f43bb1944
BLAKE2b-256 ebc601f39e7ed99f32de16debdd84ab69875e204f53f10b9646cc54dac9c4cbb

See more details on using hashes here.

Provenance

The following attestation bundles were made for secretspec-0.16.0-cp39-abi3-manylinux_2_28_x86_64.whl:

Publisher: python-wheels.yml on cachix/secretspec

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file secretspec-0.16.0-cp39-abi3-manylinux_2_28_aarch64.whl.

File metadata

File hashes

Hashes for secretspec-0.16.0-cp39-abi3-manylinux_2_28_aarch64.whl
Algorithm Hash digest
SHA256 6e407f37e63eb4708cf674197a4d0733982e645ea1e2a78f9b22a0204b036123
MD5 d147ade7c75205481cc0137589672cae
BLAKE2b-256 1b633a4037933a815ae3062d8c062e7bc34998fda6d2d65c49350903a9539f1f

See more details on using hashes here.

Provenance

The following attestation bundles were made for secretspec-0.16.0-cp39-abi3-manylinux_2_28_aarch64.whl:

Publisher: python-wheels.yml on cachix/secretspec

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file secretspec-0.16.0-cp39-abi3-macosx_11_0_arm64.whl.

File metadata

File hashes

Hashes for secretspec-0.16.0-cp39-abi3-macosx_11_0_arm64.whl
Algorithm Hash digest
SHA256 d54ebdfe8d6b315b27eeed9c338d0ebc3e240a4b512e4a9bf76eb1d0b9604b8c
MD5 122da383c7aa46037810601298c860f8
BLAKE2b-256 9d3759e80d4a6fc97e5bc3e0b38657a7ecbefb558f77bd2ff003d2b85fcd77b9

See more details on using hashes here.

Provenance

The following attestation bundles were made for secretspec-0.16.0-cp39-abi3-macosx_11_0_arm64.whl:

Publisher: python-wheels.yml on cachix/secretspec

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page