Skip to main content

Treehugger

https://travis-ci.org/timeoutdigital/treehugger.svg?branch=master

Takes care of your environment (variables) on AWS.

Requirements

  • Python 2.7+ or 3.4+

  • Some simple dependencies as listed in setup.py - boto3, PyYAML, requests, and six.

  • A KMS key in your account aliased as alias/treehugger.

How it works

Treehugger lets you use KMS encrypted environment variables to run your application on EC2. You store the encrypted variables in YAML files alongside your other configuration management, then just get them into the EC2 User Data for an instance. Treehugger can read the variables from user data, decrypt the encrypted ones, and run your application.

For example, say we want to run an application that takes a GITHUB_TOKEN environment variable for talking to GitHub. Since this is sensitive data, we want to store it encrypted and only decrypt it when running the application. You can start by writing a YAML file my_app_vars.yml that contains the variable in its unencrypted form, in a to_encrypt key in a mapping that indicates it should be encrypted:

GITHUB_TOKEN: {to_encrypt: example-token}
TREEHUGGER_APP: my-app
TREEHUGGER_STAGE: prod

The TREEHUGGER_APP and TREEHUGGER_STAGE variables are mandatory and used to provide context to Treehugger. They are used to encrypt the variables using KMS’s Encryption Context feature, giving access control and protection against tampering.

You can encrypt the file by running:

treehugger encrypt-file my_app_vars.yml

It’ll be changed to something like:

GITHUB_TOKEN: {encrypted: AQECAHiVqEdWu6BhwWXkqJrEhgPpuDXA3TC1MPUeQb...}
TREEHUGGER_APP: my-app
TREEHUGGER_STAGE: prod

Note that the plaintext variables are not encrypted, only those marked to_encrypt.

Going forwards you can edit the file with:

treehugger edit my_app_vars.yml

This will decrypt the file into a temporary file, open that in your $EDITOR, then once that finishes encrypt it back in place. This avoids any risk of accidentally committing your decrypted secrets.

For deployment, it’s up to you to get the contents of that file into the User Data of the EC2 instance of the application, underneath the key treehugger.

For example, you could pass the contents of the file as a parameter to a CloudFormation template that puts the value into the UserData property of an AutoScaling Group. For example if passed in as a parameter TreehuggerUserData (with extra indentation):

LaunchConfig:
  Type: AWS::AutoScaling::LaunchConfiguration
  Properties:
    UserData:
      Fn::Base64:
        !Sub
        - |
          treehugger:
            ${IndentedTreehuggerUserData}

Then on the EC2 instance your application can be started with:

treehugger exec -- /path/to/application

Treehugger will load the User Data as YAML, extract the dictionary under the ‘treehugger’ key, decrypt the variables marked encrypted, put them into the environment, and then replace itself with a copy of the application using execlp.

Testing

Install and run tox (docs).

Metadata

Release files for treehugger 1.0.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for treehugger 1.0.2
File Size Uploaded
treehugger-1.0.2.tar.gz 12.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for treehugger 1.0.2
File Interpreter ABI Platform
treehugger-1.0.2-py2.py3-none-any.whl Python 2, Python 3 none any Details

Total release size: 23.8 kB

Release files / treehugger-1.0.2.tar.gz

Download URL treehugger-1.0.2.tar.gz
Size 12.1 kB
Tags Source
SHA-256 checksum
How to use checksums
b8798705aaf45b6a8b437f04a81ba34d915c48062777d286d6ebcf3af612a7f6
BLAKE2b-256 checksum
How to use checksums
4af6fbb84e132b29ba5ab5b3d60ecfde4fed0b5459bf8bf97f5ca0c929ea5aa2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release files / treehugger-1.0.2-py2.py3-none-any.whl

Download URL treehugger-1.0.2-py2.py3-none-any.whl
Size 11.8 kB
Tags Python 2 Python 3
SHA-256 checksum
How to use checksums
45bbbddbd80b5615d5c79cd03c997b8dd8b07e5854848febfbc44a66c08ce8c2
BLAKE2b-256 checksum
How to use checksums
c96208dc93cefea8cdad43ab0cc714e792465619055f233305012f6c30f7e6b8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release history Release notifications | RSS feed

3.0.0

2 release files

2.3.0

3 release files

2.2.0

2 release files

2.1.0

2 release files

2.0.0

2 release files

1.2.1

2 release files

1.2.0

2 release files

1.1.0

2 release files

This release

1.0.2 This release

2 release files

1.0.1

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page