Add Secret Store Support
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 35/100
Hướng nghiên cứu
Bắt đầu với các WIT bindings trong stubs/wit_world/imports/secret_store.py và so sánh các SecretStore API và Secret API được yêu cầu với hành vi Fastly Secret Store được ghi trong tài liệu. Thêm phạm vi kiểm thử cho Viceroy bằng cách sử dụng @on_viceroy và dữ liệu secret-store inline trong test.toml. Hoàn tất khi các resource wrapper, cách truy cập dạng dict, các phương thức plaintext và các biểu diễn chuỗi không làm lộ secret đều được kiểm thử.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Overview
Add support for Fastly's Secret Store, providing secure access to sensitive credentials and secrets at the edge.
WIT Interface
interface secret-store {
resource secret {
from-bytes: static func(bytes: list<u8>) -> result<secret, error>;
plaintext: func(max-len: u64) -> result<list<u8>, error>;
}
resource store {
open: static func(name: string) -> result<store, open-error>;
get: func(key: string) -> result<option<secret>, error>;
}
}
WIT bindings: stubs/wit_world/imports/secret_store.py
API Design
- Implement
SecretStoreresource wrapper - Implement
Secretresource withplaintext()andplaintext_str()methods - Override
__str__and__repr__to return"<Secret>"to prevent accidental exposure in logs - Provide dict-like interface:
__getitem__,__contains__ from_bytes()available but discouraged (for API compatibility when secrets come from non-store sources)
Cross-SDK Comparison:
-
Rust:
SecretStore::open()withget()(panics),try_get()(fallible),contains().Secrethasplaintext()returningByteswith lazy decryption/caching. Warns against bringing secrets into memory unnecessarily. -
Go:
Open()returns*Store,Get()returns*Secret.Plaintext()decrypts to[]byte. IncludesSecretFromBytes()for non-store secrets and conveniencePlaintext(storeName, secretName)one-liner. -
JS:
new SecretStore(name), asyncget()returnsSecretStoreEntry | null. Entry hasplaintext()(UTF-8 string) andrawBytes()(Uint8Array). StaticfromBytes()for creating entry from raw data.
Recommended Python approach:
- Dict-like access:
store[key]raises if not found,store.get(key, default=None)returns None if missing - Secret object with lazy
plaintext()returningbytes, optionalplaintext_str()for UTF-8 text - Consider context manager for secrets to encourage memory cleanup
- Security warnings in docstrings about keeping secrets in memory
Viceroy Testing
Viceroy supports Secret Store with inline or file-based test data via test.toml:
[local_server]
# Inline secrets
secret_stores.my_secrets = [
{key = "api_key", data = "secret-value-123"},
{key = "cert", file = "path/to/cert.pem"},
{key = "from_env", env = "MY_ENV_VAR"}
]
# Or JSON file format
secret_stores.json_secrets = { file = "data/secrets.json", format = "json" }
Secrets can be provided inline, from files, or from environment variables. Tests can use @on_viceroy with inline TOML configuration.
Reference
- Ngôn ngữ chính
- Python
- Star
- 5
- Fork
- 1
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của fastly/compute-sdk-python
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
fastly/compute-sdk-python#116 ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
fastly/compute-sdk-python#98 ·
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
fastly/compute-sdk-python#74 ·
-
Add HTTP Downstream Metadata APIĐang mở
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
fastly/compute-sdk-python#61 ·
-
Set up Sphinx Documentation InfrastructureCó thể làm lại được @erikrose đã nhận 181 ngày trước và không có pull request nào đang mở. Đang mở
fastly/compute-sdk-python#60 · 1 người được giao ·
Tất cả issue của fastly/compute-sdk-python
Issue tương tự
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 85/100
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 75/100
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 85/100
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 85/100
data-umbrella/du-event-board#225 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100