Skip to main content

Production secret storage for the Stapel framework — OpenBao/HashiCorp Vault behind the stapel-core secret-provider seam

Project description

stapel-vault

Production secret storage for the Stapel framework. A facade over secret backends behind the stapel_core.secrets provider seam — the first backend is OpenBao / HashiCorp Vault (KV v2; their HTTP APIs are compatible, so one client speaks to both).

Local dev and the minimal preset keep reading secrets from the environment (stapel-core's default provider). In production, where env for secrets is unacceptable, point the seam at stapel-vault and the framework reads SECRET_KEY, JWT_SECRET_KEY, database passwords and LLM pool keys from Vault instead — with no change to the code that consumes them.

Install

pip install stapel-vault      # requires stapel-core with the SecretProvider seam

Wire it up

The provider is selected at settings-bootstrap time (production settings resolve SECRET_KEY before django.setup()), via environment — which is also where Vault's own connection/auth config belongs:

# control plane only — never a workload container (see MODULE.md, S1)
export STAPEL_SECRETS_PROVIDER=stapel_vault.VaultSecretProvider
export VAULT_ADDR=https://vault.internal:8200
export VAULT_K8S_ROLE=stapel-web       # Kubernetes auth (phase 2)

Then any stapel_core.secrets.get_secret("DJANGO_SECRET_KEY") — including the SECRET_KEY / JWT_SECRET_KEY reads in stapel_core.django.settings — comes from Vault. A missing secret is a hard, loud boot failure (fail_closed), not a silent None.

Secret layout (default convention)

A service's secrets are keys of one KV v2 secret (the "bundle") at secret/data/<prefix>/<app> (defaults secret/data/stapel/app):

bao kv put secret/stapel/app \
    DJANGO_SECRET_KEY=... JWT_SECRET_KEY=... POSTGRES_PASSWORD=...

DJANGO_SECRET_KEY then resolves to GET v1/secret/data/stapel/app.data.data["DJANGO_SECRET_KEY"]. Override per name with VAULT_SECRET_MAP (JSON). See MODULE.md for the full config reference, auth methods, rotation, and the deploy-mode map.

Auth methods

Method When Config
token local/dev VAULT_TOKEN
kubernetes prod on k8s (phase 2) VAULT_K8S_ROLE (+ projected SA JWT)
approle prod, non-k8s VAULT_ROLE_ID + VAULT_SECRET_ID

Auto-detected from what is present, or forced with VAULT_AUTH_METHOD.

License

MIT — see LICENSE.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

stapel_vault-0.1.0.tar.gz (18.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

stapel_vault-0.1.0-py3-none-any.whl (15.7 kB view details)

Uploaded Python 3

File details

Details for the file stapel_vault-0.1.0.tar.gz.

File metadata

  • Download URL: stapel_vault-0.1.0.tar.gz
  • Upload date:
  • Size: 18.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for stapel_vault-0.1.0.tar.gz
Algorithm Hash digest
SHA256 91fdcd7b47020da1ac2507f72c639d8976b5847ac23eba53f032e44b21e5d90a
MD5 ae1b0d02fde5865a35f10f33080bc3e6
BLAKE2b-256 dad42f5f99a36552bd608a1aff1df85d0910c496d4ec0d834c92cc60b498654c

See more details on using hashes here.

Provenance

The following attestation bundles were made for stapel_vault-0.1.0.tar.gz:

Publisher: publish.yml on usestapel/stapel-vault

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file stapel_vault-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: stapel_vault-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 15.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for stapel_vault-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 4fdd4e812f89ebbfc6a7221e9574b73453cdbaa4dbc8c34905e90f2df4fab136
MD5 cc57330aababb20a02692d811de6bb9e
BLAKE2b-256 61bd00680e04fed9cb3179f66b469a86c47f2361f59f36b541fdf34b60517a29

See more details on using hashes here.

Provenance

The following attestation bundles were made for stapel_vault-0.1.0-py3-none-any.whl:

Publisher: publish.yml on usestapel/stapel-vault

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page