Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Add Secret Store Support

Đang mở
#50 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức phù hợp với người mới
35/100
Loại issue
Tính năng
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Đình trệ
Công nghệ
python
Lĩnh vực
backend, security

Hướng nghiên cứu

Bắt đầu với các WIT bindings trong stubs/wit_world/imports/secret_store.py và so sánh các SecretStore API và Secret API được yêu cầu với hành vi Fastly Secret Store được ghi trong tài liệu. Thêm phạm vi kiểm thử cho Viceroy bằng cách sử dụng @on_viceroy và dữ liệu secret-store inline trong test.toml. Hoàn tất khi các resource wrapper, cách truy cập dạng dict, các phương thức plaintext và các biểu diễn chuỗi không làm lộ secret đều được kiểm thử.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Overview

Add support for Fastly's Secret Store, providing secure access to sensitive credentials and secrets at the edge.

WIT Interface

interface secret-store {
  resource secret {
    from-bytes: static func(bytes: list<u8>) -> result<secret, error>;
    plaintext: func(max-len: u64) -> result<list<u8>, error>;
  }

  resource store {
    open: static func(name: string) -> result<store, open-error>;
    get: func(key: string) -> result<option<secret>, error>;
  }
}

WIT bindings: stubs/wit_world/imports/secret_store.py

API Design

  • Implement SecretStore resource wrapper
  • Implement Secret resource with plaintext() and plaintext_str() methods
  • Override __str__ and __repr__ to return "<Secret>" to prevent accidental exposure in logs
  • Provide dict-like interface: __getitem__, __contains__
  • from_bytes() available but discouraged (for API compatibility when secrets come from non-store sources)

Cross-SDK Comparison:

  • Rust: SecretStore::open() with get() (panics), try_get() (fallible), contains(). Secret has plaintext() returning Bytes with lazy decryption/caching. Warns against bringing secrets into memory unnecessarily.

  • Go: Open() returns *Store, Get() returns *Secret. Plaintext() decrypts to []byte. Includes SecretFromBytes() for non-store secrets and convenience Plaintext(storeName, secretName) one-liner.

  • JS: new SecretStore(name), async get() returns SecretStoreEntry | null. Entry has plaintext() (UTF-8 string) and rawBytes() (Uint8Array). Static fromBytes() for creating entry from raw data.

Recommended Python approach:

  • Dict-like access: store[key] raises if not found, store.get(key, default=None) returns None if missing
  • Secret object with lazy plaintext() returning bytes, optional plaintext_str() for UTF-8 text
  • Consider context manager for secrets to encourage memory cleanup
  • Security warnings in docstrings about keeping secrets in memory

Viceroy Testing

Viceroy supports Secret Store with inline or file-based test data via test.toml:

[local_server]
# Inline secrets
secret_stores.my_secrets = [
  {key = "api_key", data = "secret-value-123"},
  {key = "cert", file = "path/to/cert.pem"},
  {key = "from_env", env = "MY_ENV_VAR"}
]

# Or JSON file format
secret_stores.json_secrets = { file = "data/secrets.json", format = "json" }

Secrets can be provided inline, from files, or from environment variables. Tests can use @on_viceroy with inline TOML configuration.

Reference

Ngôn ngữ chính
Python
Star
5
Fork
1
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của fastly/compute-sdk-python

Tất cả issue của fastly/compute-sdk-python

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.