Repository navigation
Releases: zach-source/opx
Release list
v0.9.0
🎉 opx v0.9.0 - 1Password CLI Batching Daemon
🔒 Security Features
- Session Idle Timeout: Configurable automatic locking (default: 8 hours)
- TLS Encryption: All client-server communication encrypted
- Input Validation: Command injection and race condition protection
- Cache Security: Automatic clearing when sessions lock
🌐 Modern Unix Integration
- XDG Base Directory: Full compliance with proper config/data separation
- Backward Compatibility: Existing
~/.op-authd/installations preserved
⚡ Performance & Reliability
- Request Coalescing: Eliminates duplicate concurrent secret reads
- Thread-Safe: Robust concurrent access throughout
- Memory Management: Automated cleanup with configurable intervals
Changelog
Features
- cdd487a: feat: sign release checksums with the maintainer's GPG key (@zach-source)
Others
- 1438c88: Merge pull request #3 from zach-source/fix/release-script-token-and-sign-gate (@zach-source)
- 4675b27: Merge pull request #4 from zach-source/feat/sign-release-checksums (@zach-source)
- 70eacd4: Merge pull request #5 from zach-source/fix/push-tag-before-release (@zach-source)
- 7973129: fix: make the release script survive a missing token or GPG key (@zach-source)
- 2aa8e43: fix: push the release tag before GoReleaser runs (@zach-source)
📦 Installation
Download binaries for your platform from the assets below.
Make binaries executable:
chmod +x op-authd opxQuick Start:
# Start daemon (8-hour session timeout)
./op-authd --verbose
# Use client to read secrets
./opx read "op://Engineering/DB/password"🔍 Security Verification
# Verify checksums
sha256sum -c checksums.txt
# Verify GPG signature (if available)
gpg --verify checksums.txt.sig checksums.txt📋 Requirements
- 1Password CLI must be installed and authenticated
- Linux or macOS (Windows support planned)
v0.8.0
🎉 opx v0.8.0 - 1Password CLI Batching Daemon
🔒 Security Features
- Session Idle Timeout: Configurable automatic locking (default: 8 hours)
- TLS Encryption: All client-server communication encrypted
- Input Validation: Command injection and race condition protection
- Cache Security: Automatic clearing when sessions lock
🌐 Modern Unix Integration
- XDG Base Directory: Full compliance with proper config/data separation
- Backward Compatibility: Existing
~/.op-authd/installations preserved
⚡ Performance & Reliability
- Request Coalescing: Eliminates duplicate concurrent secret reads
- Thread-Safe: Robust concurrent access throughout
- Memory Management: Automated cleanup with configurable intervals
Changelog
Features
- 390c562: feat: default cache TTL to 4h and keep the session alive that long (@zach-source)
- 6727fdb: feat: encrypted disk cache so restarts stay warm (@zach-source)
- 9dd3e31: feat: export opx from this flake with a darwin home-manager module (@zach-source)
- b02d0f4: feat: opt-in background revalidation to catch out-of-band rotations (@zach-source)
- c685fc1: feat: opx invalidate, so a rotation can drop the cache immediately (@zach-source)
Others
- 5fa210e: Merge pull request #2 from zach-source/revive/opx-hot-cache (@zach-source)
- cb3bd90: fix: address security review findings on the hot cache (@zach-source)
- d96bd16: fix: cap the cache TTL to the session lock window instead of extending it (@zach-source)
- 4aa5fc5: fix: commit go.sum and add CI to keep the tree buildable (@zach-source)
- c8c14a0: fix: read the HMAC key fallback file back, not just write it (@zach-source)
📦 Installation
Download binaries for your platform from the assets below.
Make binaries executable:
chmod +x op-authd opxQuick Start:
# Start daemon (8-hour session timeout)
./op-authd --verbose
# Use client to read secrets
./opx read "op://Engineering/DB/password"🔍 Security Verification
# Verify checksums
sha256sum -c checksums.txt
# Verify GPG signature (if available)
gpg --verify checksums.txt.sig checksums.txt📋 Requirements
- 1Password CLI must be installed and authenticated
- Linux or macOS (Windows support planned)
opx v0.7.0
See commit history for details: v0.6.0...v0.7.0
opx v0.6.0
See commit history for details: v0.5.0...v0.6.0
opx v0.5.0
See commit history for details: v0.4.0...v0.5.0
opx v0.4.0 - Argument Parsing Fix
🐛 Bug Fixes
Fixed: Multi-Account Flag Positioning
--accountflag now works both before and after command- Previously only worked:
opx --account=X read "op://..." - Now also works:
opx read "op://..." --account=X
🔧 Improvements
- Refactored argument parsing into single tested function
- Added comprehensive test suite (19 test cases)
- Simplified main() from ~50 lines to 3 lines
- Performance: 136 ns/op with minimal allocations
📦 Artifacts
- Server and client distributed separately
- macOS binaries (arm64) - Code signed
- SHA256 checksums included
Note: Binaries are signed with Apple Development certificate. For production use, you may need to allow the app in System Preferences > Security & Privacy.
Full changelog: v0.3.0...v0.4.0
opx v0.3.0 - Enhanced Version Command and Policy Debugging
🔍 opx v0.3.0 - Enhanced Debugging and Version Information
🆕 Enhanced Version Command
- Server process detection: Shows which daemon executable is actually running
- Command line display: Full daemon command with flags and arguments
- Configuration debugging: Identify client/server version mismatches
- Process identification: Distinguish between Nix/Homebrew/local daemon installations
🛠️ Policy Debugging Tools
- Policy state machine: Step-by-step rule evaluation with detailed breakdown
- Audit failure analysis: Quick identification of access denials with reasons
- Interactive debugging: Visual policy evaluation with ✅/❌ indicators
- Consistent policy testing: Fixed discrepancy between test and debug commands
🔧 New Commands
# Enhanced version information
opx version # Shows client version + server process info
# Comprehensive policy debugging
opx policy debug <path> <ref> # Detailed rule evaluation breakdown
opx audit failures --since=1h # Quick denial analysis with reasons
# Server version
opx-authd --version # Shows daemon version and exits📦 Installation (macOS ARM64)
Download signed binaries for Apple Silicon Macs.
💡 Debugging Benefits
- Configuration troubleshooting: Identify daemon path and command line mismatches
- Policy analysis: Complete rule evaluation with failure point identification
- Audit investigation: Quick access denial analysis with suggested fixes
- Version verification: Ensure client/server compatibility
This release provides professional debugging tools for comprehensive troubleshooting of access control and configuration issues.
opx v0.2.0 - Policy Debugging and Audit Failure Analysis
🔍 opx v0.2.0 - Advanced Policy Debugging Tools
🛠️ Policy Debugging and Audit Enhancements
- Policy State Machine: Step-by-step rule evaluation with detailed breakdown
- Enhanced Audit Analysis: Quick failure identification with automatic policy suggestions
- Interactive Debugging: Visual policy evaluation with pass/fail indicators
- HMAC Audit Support: Complete audit log parsing for signed and legacy formats
🔧 New Debugging Commands
# Detailed policy rule evaluation
opx policy debug <process-path> <reference>
# Quick failure analysis
opx audit failures --since=1h --process=/path/to/binary
# Enhanced policy testing
opx policy test <process-path> <reference>🎯 Problem Resolution Tools
- Root cause analysis: Identify exact policy condition failures
- Visual indicators: ✅/❌ for each policy check (Path, Signing, References)
- Failure suggestions: Automatic recommendations for policy fixes
- Real-time debugging: Immediate policy evaluation without daemon restart
This release provides enterprise-grade policy debugging and audit analysis tools for comprehensive access control troubleshooting.
opx v0.1.2 - macOS Security Framework Integration
🎉 opx v0.1.2 - Advanced macOS Security Integration
🔒 Enhanced Security Features
- Parent Process Verification: Cryptographic validation of entire process hierarchy
- Code Signing Validation: Complete binary signature verification
- Anti-Spoofing Protection: PID-to-executable verification prevents attacks
- Rich Audit Context: Process hierarchy with verification status
📦 Installation (macOS Only)
This release focuses on macOS with Security framework integration.
Build from source:
git clone https://github.com/zach-source/opx.git
cd opx
git checkout v0.1.2
make build🚀 Quick Start
# Start daemon
./bin/opx-authd --enable-audit-log --verbose
# Login and read secrets
./bin/opx login --account=YOUR_ACCOUNT
./bin/opx read "op://vault/item/field"System Requirements: macOS (Intel or Apple Silicon), 1Password CLI