Repository navigation
feat: clean up secrets removed from the config with profile prune - #34
Merged
Merged
Conversation
Removing a secret from config.yml left it behind: `unload` only unset configured secrets, so a removed variable stayed in the shell and a removed SSH key stayed in ssh-agent, and its cached value stayed in the keychain until `profile clear` wiped the whole profile. - `unload` also unsets the secrets recorded as loaded and removes the SSH keys keysafe recorded adding, even if the config no longer names them; `unload <NAME>` accepts those names too. - `profile prune <profile>` deletes cached secrets the config no longer names (under keysafe.<profile> and op-secrets-<profile>) and removes their SSH keys from ssh-agent, keeping the profile loaded. For a profile removed from the config, it deletes everything keysafe kept of it and forgets it. - `doctor` warns about orphaned keychain items, profiles recorded as loaded that the config no longer has, and orphaned keys ssh-agent still holds, and suggests `profile prune`. `load` doesn't prune: the cache is only cleaned when asked. Closes #33
`doctor` suggested `profile clear` for items zsh-op left under op-secrets-<profile>, which wipes the whole cache, while `profile prune` now removes exactly the leftovers the config no longer names. The warning counts only those items, since configured ones move to keysafe.<profile> when they are read, and suggests `profile prune`. The help of `profile clear` and `profile prune` now mentions the other.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Removing a secret from
config.ymlleft it behind:unloadonly unset configured secrets, so a removed variable stayed in the shell, a removed SSH key stayed in ssh-agent, and its cached value stayed in the keychain untilprofile clearwiped the whole profile.unloadalso unsets the secrets recorded as loaded and removes the SSH keys keysafe recorded adding, even if the config no longer names them.unload <NAME>accepts those names too; names keysafe never loaded still fail with "not found".profile prune <profile>(new) deletes cached secrets the config no longer names, underkeysafe.<profile>andop-secrets-<profile>, and removes their SSH keys from ssh-agent. The profile stays loaded, sounloadstill knows the removed names. For a profile removed from the config, it deletes everything keysafe kept of it and forgets it; a name keysafe has nothing for still fails with "profile not found".doctorwarns about orphaned keychain items, profiles recorded as loaded that the config no longer has, and orphaned keys ssh-agent still holds, each with theprofile prunecommand that removes them.doctor's zsh-op warning now suggestsprofile pruneinstead ofprofile clear, and counts only the leftovers the config no longer names (configured ones move tokeysafe.<profile>when read). With that,doctoronly ever suggestsprune;clearstays the "start over" command, and the help of each mentions the other.loaddoesn't prune: we chose to report orphans indoctorand clean up only when asked.Not covered:
doctorcan't find its keychain items (the keychain is searched by exact service name).profile prune <name>still removes them.unloadruns there.Tested with unit tests for the cache,
unload,profile pruneanddoctor(all 163 tests pass, clippy clean). Not yet tried against a real keychain and ssh-agent.Closes #33