Skip to content

v0.19.0 — local tools fill roles from vault items

Choose a tag to compare

@jfbauer jfbauer released this 27 Sep 14:03
d178f0d

A sealed secret reaches the machine again. The bridge opens the vault's current wrap (context-bound, signature required), strips the vault's padding, and matches secrets by id. Engram's cross-repo test now runs the browser vault code against this bridge's code.

Roles are filled from vault items. A resolved call carries each role's item: plain fields, and for each sealed field the secret id and its space. The tool gets ENGRAM_<ROLE>_<FIELD>; only sealed values are scrubbed from output. Values may come from several spaces in one call.

Also removes a node_modules symlink committed by mistake in v0.18.0's history.

Needs an Engram with vault items (feat/vault-items); local tools are unaffected for servers that do not use them.