feat(notsecrets): add multi-provider secret resolution system
Some checks failed
Public Repo Readiness / Check Public Repo Readiness (push) Has been cancelled

Add a config-driven, strongly-typed secret/env resolution system to
notsecrets with 11 provider backends. The system supports explicit
key bindings with typed SecretRef enums and a priority chain fallback.

Tier 1 providers (implemented): Env, 1Password, dotenvx, SOPS, GSM
Tier 2 providers (stubbed): nuenv, direnv, mise, Bitwarden, Vault, dotenvy

New types: Provider, ProviderConfig, SecretRef, SecretsConfig,
SecretsError, SecretSource, EnumerableSecretSource, SecretResolver

Config lives in notsecrets.toml with typed serde deserialization.
ISP split: EnumerableSecretSource for backends that support bulk
enumeration, SecretSource for single-key lookup only.

Includes conformance test suite, 33 new tests (161 workspace total).
notstrap EnvInjector migration deferred to follow-up.
This commit is contained in:
2026-06-06 09:49:05 -04:00
parent 65d1a2dc2e
commit 1359def673
27 changed files with 3079 additions and 39 deletions

View File

@@ -1,10 +1,30 @@
pub mod bitwarden;
pub mod direnv;
pub mod dotenvx;
pub mod dotenvy;
pub mod env;
pub mod file;
pub mod gsm;
pub mod mise;
pub mod nuenv;
pub mod op;
pub mod prompt;
pub mod sops;
pub mod vault;
pub mod yubikey;
pub use crate::ports::IdentitySource;
pub use bitwarden::BitwardenSource;
pub use direnv::DirenvSource;
pub use dotenvx::DotenvxSource;
pub use dotenvy::DotenvySource;
pub use env::EnvSource;
pub use file::FileSource;
pub use gsm::GsmSource;
pub use mise::MiseSource;
pub use nuenv::NuenvSource;
pub use op::OpSource;
pub use prompt::PromptSource;
pub use sops::SopsSource;
pub use vault::VaultSource;
pub use yubikey::YubikeySource;