Skip to content

feat: clean up secrets removed from the config with profile prune - #34

Merged
iamralch merged 2 commits into
mainfrom
feat/prune-orphaned-secrets
Oct 7, 2026
Merged

iamralch merged 2 commits into
mainfrom
feat/prune-orphaned-secrets

Conversation

@iamralch

@iamralch iamralch commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Removing a secret from config.yml left it behind: unload only unset configured secrets, so a removed variable stayed in the shell, a removed SSH key stayed in ssh-agent, and its cached value stayed in the keychain until profile clear wiped the whole profile.

  • unload also unsets the secrets recorded as loaded and removes the SSH keys keysafe recorded adding, even if the config no longer names them. unload <NAME> accepts those names too; names keysafe never loaded still fail with "not found".

  • profile prune <profile> (new) deletes cached secrets the config no longer names, under keysafe.<profile> and op-secrets-<profile>, and removes their SSH keys from ssh-agent. The profile stays loaded, so unload still knows the removed names. For a profile removed from the config, it deletes everything keysafe kept of it and forgets it; a name keysafe has nothing for still fails with "profile not found".

  • doctor warns about orphaned keychain items, profiles recorded as loaded that the config no longer has, and orphaned keys ssh-agent still holds, each with the profile prune command that removes them.

  • doctor's zsh-op warning now suggests profile prune instead of profile clear, and counts only the leftovers the config no longer names (configured ones move to keysafe.<profile> when read). With that, doctor only ever suggests prune; clear stays the "start over" command, and the help of each mentions the other.

load doesn't prune: we chose to report orphans in doctor and clean up only when asked.

Not covered:

  • A profile unloaded before it was removed from the config has no record left, so doctor can't find its keychain items (the keychain is searched by exact service name). profile prune <name> still removes them.
  • Variables already set in other open shells stay until unload runs there.
  • The config validation message mentioned in the issue is left for a separate change.

Tested with unit tests for the cache, unload, profile prune and doctor (all 163 tests pass, clippy clean). Not yet tried against a real keychain and ssh-agent.

Closes #33

Removing a secret from config.yml left it behind: `unload` only unset
configured secrets, so a removed variable stayed in the shell and a
removed SSH key stayed in ssh-agent, and its cached value stayed in the
keychain until `profile clear` wiped the whole profile.

- `unload` also unsets the secrets recorded as loaded and removes the
  SSH keys keysafe recorded adding, even if the config no longer names
  them; `unload <NAME>` accepts those names too.
- `profile prune <profile>` deletes cached secrets the config no longer
  names (under keysafe.<profile> and op-secrets-<profile>) and removes
  their SSH keys from ssh-agent, keeping the profile loaded. For a
  profile removed from the config, it deletes everything keysafe kept of
  it and forgets it.
- `doctor` warns about orphaned keychain items, profiles recorded as
  loaded that the config no longer has, and orphaned keys ssh-agent
  still holds, and suggests `profile prune`.

`load` doesn't prune: the cache is only cleaned when asked.

Closes #33
`doctor` suggested `profile clear` for items zsh-op left under
op-secrets-<profile>, which wipes the whole cache, while `profile prune`
now removes exactly the leftovers the config no longer names. The
warning counts only those items, since configured ones move to
keysafe.<profile> when they are read, and suggests `profile prune`.

The help of `profile clear` and `profile prune` now mentions the other.
@iamralch iamralch self-assigned this Oct 7, 2026
@iamralch iamralch added the bug Something isn't working label Oct 7, 2026
@iamralch
iamralch merged commit 01c105b into main Oct 7, 2026
9 checks passed
@iamralch
iamralch deleted the feat/prune-orphaned-secrets branch October 7, 2026 05:44
@ralch ralch Bot mentioned this pull request Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Clean up secrets removed from the config (unload, load prune, status)

1 participant