Give every new unlocker a directory of its own (closes #71)
check / check (push) Failing after 1s

A passphrase unlocker added to a vault that had one, and a PGP, keychain
or Secure Enclave unlocker added on the same day as another of its type,
were written into the existing unlocker's directory file by file, so a
crash part-way left a current unlocker whose files did not belong
together.

Unlocker directories, keychain items and Secure Enclave keys are now
named with the time to the nanosecond, and secret.WriteDir refuses a
directory that exists. Adding a passphrase unlocker writes the new one,
points current-unlocker at it, and only then removes the vault's other
passphrase unlockers.

Model: opus-5-5
This commit was merged in pull request #99.
This commit is contained in:
2026-10-04 16:58:45 +02:00
parent db7d2c952e
commit 7e4e0f7806
13 changed files with 309 additions and 70 deletions
+6 -3
View File
@@ -197,6 +197,9 @@ Creates a new unlocker of the specified type:
**Options:**
- `--keyid <id>`: GPG key ID (optional for PGP type, uses default key if not specified)
A vault has one passphrase unlocker: adding one replaces the one the vault
has, which is removed only once the new one is the current unlocker.
#### `secret unlocker remove <unlocker-id> [--force]` / `secret unlocker rm` ⚠️ 🛑
**DANGER**: Permanently removes an unlocker. Like Unix `rm`, this command
@@ -243,8 +246,8 @@ Decrypts data using an Age key stored as a secret.
├── vaults.d/
│ ├── default/
│ │ ├── unlockers.d/
│ │ │ ├── passphrase/ # Passphrase unlocker
│ │ │ └── pgp/ # PGP unlocker
│ │ │ ├── passphrase-<time>/ # Passphrase unlocker
│ │ │ └── <host>-pgp-<time>/ # PGP unlocker
│ │ ├── secrets.d/
│ │ │ ├── api%key/ # Secret: api/key
│ │ │ │ ├── versions/
@@ -260,7 +263,7 @@ Decrypts data using an Age key stored as a secret.
│ │ │ └── current -> versions/20231215.001
│ │ ├── vault-metadata.json # Vault metadata
│ │ ├── pub.age # Long-term public key
│ │ └── current-unlocker -> ../unlockers.d/passphrase
│ │ └── current-unlocker # Current unlocker's directory name
│ └── work/
│ ├── unlockers.d/
│ ├── secrets.d/