Skip to main content

A reusable python vault utility service for other projects to use hashicorp vault

Project description

Vault Service

The Vault Service package provides a convenient interface for interacting with HashiCorp Vault. It offers various methods to manage secrets for both services and tenants.

Table of Contents

Installation

You can install the Vault Service package using pip:

pip install vault-service

Usage

To use the Vault Service, you need to initialize the VaultController and then call the utility functions. Make sure to set the required environment variables for Vault connection:

export VAULT_ADDR='https://your-vault-address'
export APP_ROLE_ID='your-app-role-id'
export APP_SECRET_ID='your-app-secret-id'

Methods

Service Methods

store_service_secret(root_path: str, sub_path: str, secret_name: str, secret_data: SecretData, credentials: dict)

Stores a new secret in HashiCorp Vault under the "secret" mount path.

Parameters:

  • root_path: The root path in Vault
  • sub_path: The sub path in Vault
  • secret_name: The name of the secret to store
  • secret_data: An instance of SecretData, containing the secret information
  • credentials: Dictionary containing Vault credentials:
    {
        'app_role_id': 'your-app-role-id',
        'app_secret_id': 'your-app-secret-id'
    }
    

Returns:

  • dict: Response object containing:
    • status: "success" or "error"
    • message: Description of the operation result

Sample Payload for secret_data:

{
  "auth_key": "<auth-key>",
  "database_credentials": {
    "host": "localhost",
    "port": 5432,
    "database": "my_database",
    "user": "my_user",
    "password": "my_password"
  },
  "redis_credentials": {
    "host": "localhost",
    "port": 6379,
    "password": "my_password"
  }
}

get_service_secret(root_path: str, sub_path: str, secret_name: str, credentials: dict)

Retrieves a secret from HashiCorp Vault.

Parameters:

  • root_path: The root path in Vault.
  • sub_path: The sub path in Vault.
  • secret_name: The name of the secret to retrieve.
  • credentials: Dictionary containing Vault credentials.

Returns:

  • dict: Response object containing:
    • status: "success" or "error"
    • message: Description of the operation result
    • data: The retrieved secret data (when successful)

update_service_secret(root_path: str, sub_path: str, secret_name: str, secret_data: SecretData, credentials: Optional[dict] = None)

Updates an existing secret in HashiCorp Vault for the specified service, tenant, and secret name.

Parameters:

  • root_path: The root path in Vault
  • sub_path: The sub path in Vault
  • secret_name: The name of the secret to update
  • secret_data: An instance of SecretData, containing the updated secret information
  • credentials: Optional dictionary containing Vault credentials:
    {
        'app_role_id': 'your-app-role-id',
        'app_secret_id': 'your-app-secret-id'
    }
    

Returns: A message indicating the success or failure of the operation.

Sample Payload for secret_data:

{
  "auth_key": "<new-auth-key>",
  "database_credentials": {
    "host": "localhost",
    "port": 5432,
    "database": "my_database",
    "user": "my_user",
    "password": "new_password"
  },
  "redis_credentials": {
    "host": "localhost",
    "port": 6379,
    "password": "new_password"
  }
}

delete_service_secret(root_path: str, sub_path: str, secret_name: str, credentials: dict)

Deletes a secret from HashiCorp Vault for the specified service, tenant, and secret name.

Parameters:

  • root_path: The root path in Vault
  • sub_path: The sub path in Vault
  • secret_name: The name of the secret to delete.

Returns: A message indicating the success or failure of the deletion.


Tenant Methods

store_tenant_secret(tenant_id: str, sub_path: str, secret_name: str, secret_data: SecretData, credentials: dict)

Stores a new secret in HashiCorp Vault under the "tenant" mount path.

Parameters:

  • tenant_id: The ID of the tenant
  • sub_path: The sub path in Vault
  • secret_name: The name of the secret to store
  • secret_data: An instance of SecretData, containing the secret information
  • credentials: Dictionary containing Vault credentials:
    {
        'app_role_id': 'your-app-role-id',
        'app_secret_id': 'your-app-secret-id'
    }
    

Returns:

  • dict: Response object containing:
    • status: "success" or "error"
    • message: Description of the operation result

Sample Payload for secret_data:

{
  "auth_key": "<auth-key>",
  "database_credentials": {
    "host": "localhost",
    "port": 5432,
    "database": "my_database",
    "user": "my_user",
    "password": "my_password"
  },
  "redis_credentials": {
    "host": "localhost",
    "port": 6379,
    "password": "my_password"
  }
}

get_tenant_secret(tenant_id: str, sub_path: str, secret_name: str, credentials: dict)

Retrieves a secret from HashiCorp Vault under the tenant mount path.

Parameters:

  • tenant_id: The ID of the tenant
  • sub_path: The sub path in Vault
  • secret_name: The name of the secret to retrieve
  • credentials: Dictionary containing Vault credentials

Returns:

  • dict: Response object containing:
    • status: "success" or "error"
    • message: Description of the operation result
    • data: The retrieved secret data (when successful)

update_tenant_secret(tenant_id: str, sub_path: str, secret_name: str, secret_data: SecretData, credentials: dict)

Updates an existing secret in HashiCorp Vault under the tenant mount path.

Parameters:

  • tenant_id: The ID of the tenant
  • sub_path: The sub path in Vault
  • secret_name: The name of the secret to update
  • secret_data: An instance of SecretData, containing the updated secret information
  • credentials: Dictionary containing Vault credentials:
    {
        'app_role_id': 'your-app-role-id',
        'app_secret_id': 'your-app-secret-id'
    }
    

Returns: A message indicating the success or failure of the operation.

Sample Payload for secret_data:

{
  "auth_key": "<new-auth-key>",
  "database_credentials": {
    "host": "localhost",
    "port": 5432,
    "database": "my_database",
    "user": "my_user",
    "password": "new_password"
  },
  "redis_credentials": {
    "host": "localhost",
    "port": 6379,
    "password": "new_password"
  }
}

delete_tenant_secret(tenant_id: str, sub_path: str, secret_name: str, credentials: dict)

Deletes a secret from HashiCorp Vault under the tenant mount path.

Parameters:

  • tenant_id: The ID of the tenant
  • sub_path: The sub path in Vault
  • secret_name: The name of the secret to delete
  • credentials: Dictionary containing Vault credentials

Returns: A message indicating the success or failure of the deletion.

License

This project is licensed under the MIT License. See the LICENSE file for details.


### Changes:
- Added `tenant_id` as the first required parameter for each method.
- Specified that `tenant_id` is not optional in each method.
- Added `credentials` parameter to each method signature.
- Specified that `credentials` is optional in each method documentation.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

vault_service-1.3.2.tar.gz (8.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

vault_service-1.3.2-py3-none-any.whl (8.1 kB view details)

Uploaded Python 3

File details

Details for the file vault_service-1.3.2.tar.gz.

File metadata

  • Download URL: vault_service-1.3.2.tar.gz
  • Upload date:
  • Size: 8.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.5

File hashes

Hashes for vault_service-1.3.2.tar.gz
Algorithm Hash digest
SHA256 4a2e4baa91b221654a4c3493bf850d10a3d59bb949f8596c8a7bbd3ac9195900
MD5 329b785071449c767a6657dbc15f0676
BLAKE2b-256 45274b76961bfb5d8f9f7d65a7fcb7d1caa24a137f3e4f3105ed66e511159396

See more details on using hashes here.

File details

Details for the file vault_service-1.3.2-py3-none-any.whl.

File metadata

  • Download URL: vault_service-1.3.2-py3-none-any.whl
  • Upload date:
  • Size: 8.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.5

File hashes

Hashes for vault_service-1.3.2-py3-none-any.whl
Algorithm Hash digest
SHA256 73a47193edeffdf9c98d1b5a5e5f06f9a7810010d291fc7a5dbc332de2731bd1
MD5 1504d1766c261dcd7e66a912ed3b148e
BLAKE2b-256 5597e678f21c66f615445a859172dfea97301ffc0d543aea9463bf310ddd043e

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page