Skip to main content
https://img.shields.io/travis/praekeltfoundation/django-vaultkeeper-adaptor/master.svg?style=flat-square https://img.shields.io/codecov/c/github/praekeltfoundation/django-vaultkeeper-adaptor/master.svg?style=flat-square

A small library that allows Django applications to consume vaultkeeper output as resource secrets.

django-vaultkeeper-adaptor supports the SET_ROLE operation necessary to revoke dynamically-generated PostgreSQL credentials.

Installing the Package

Clone this project and install the package from source with the following commands in the root directory of the repository:
$ pip install -e .

Install the package for development with the following command:

$ pip install -e .[test]

Prerequisites

Technically, you do not need to launch your application with vaultkeeper to use this library, as it is simply an input adaptor. However, using your app with vaultkeeper is strongly recommended.

It is assumed that the rest of your Vault workflow is already configured and running. If you are using the PostgreSQL secret backend with Django, it is necessary to use django-postgresql-setrole in your application as well.

How to Use

Ensure that django-vaultkeeper-adaptor is installed in your production environment.

Ensure that your Django application knows where the file containing your secrets will be. In your settings.py, replace your existing way of populating DATABASES and BROKER_URL with the following code:
cfg = environ.get('CREDENTIAL_PATH','')

if cfg != '':
    vk_adaptor = vaultkeeper_adaptor.VKAdaptor(
        config_path=cfg,
        DATABASES=DATABASES,
        BROKER_URL=BROKER_URL,
    )
    vk_adaptor.process_all()

django-vaultkeeper-adaptor will read the vaultkeeper-generated file containing application credentials and populate the supplied settings variables with values from the file, if they exist.

Note that CREDENTIAL_PATH in the above example is an environment variable set with the output location of vaultkeeper secrets. You can supply your application with this value in a different manner if you wish.

Release files for vaultkeeper-adaptor 0.0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vaultkeeper-adaptor 0.0.1
File Size Uploaded
vaultkeeper_adaptor-0.0.1.tar.gz 3.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vaultkeeper-adaptor 0.0.1
File Interpreter ABI Platform
vaultkeeper_adaptor-0.0.1-py2-none-any.whl Python 2 none any Details

Total release size: 9.7 kB

Release files / vaultkeeper_adaptor-0.0.1.tar.gz

Download URL vaultkeeper_adaptor-0.0.1.tar.gz
Size 3.4 kB
Tags Source
SHA-256 checksum
How to use checksums
806b8e095dd6e21f1056ccb26f4d6b5bb13cea7e056c809079662849eb6efee4
BLAKE2b-256 checksum
How to use checksums
8776f3ad8499f4d7792b45fa4108096fa62f393e3fa984a085fcdbdc62bc3584
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release files / vaultkeeper_adaptor-0.0.1-py2-none-any.whl

Download URL vaultkeeper_adaptor-0.0.1-py2-none-any.whl
Size 6.3 kB
Tags Python 2
SHA-256 checksum
How to use checksums
0e691d66285da77e2cca6c9c335a7d0401d9ad812e72253c74f34e4cd2e67152
BLAKE2b-256 checksum
How to use checksums
34c9ed3cd109a252666539ce756ffe162776e957c598dcb7560236349f74aeec
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release history Release notifications | RSS feed

This release

0.0.1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page