@automic-vault/varlock-plugin
v0.1.0
Published
Varlock resolver for Automic Vault
Maintainers
Readme
Automic Vault for Varlock
Use Automic Vault Secrets from a Varlock schema without
invoking the av CLI at runtime.
[!IMPORTANT] Requires Automic Vault 3.9.0 or newer. Varlock requests require Approval on every run; Automic Authorization and Blessings are not supported yet.
Install
Install Automic Vault in /Applications, then add Varlock and the plugin:
$ npm install --save-dev varlock @automic-vault/varlock-plugin
$ av save API_TOKEN
# Store the Secret Value in Automic VaultUse
Add .env.schema:
# @plugin(@automic-vault/varlock-plugin)
# @disableProcessEnvInjection
# ---
# @sensitive @required
API_TOKEN=av()Load Varlock, then read Secrets through ENV rather than process.env:
import 'varlock/auto-load';
import { ENV } from 'varlock/env';
const response = await fetch('https://api.example.com/me', {
headers: { Authorization: `Bearer ${ENV.API_TOKEN}` },
});The resolver infers the Secret Name from the item name. Pass an explicit name
when they differ: API_TOKEN=av(ACTUAL_SECRET_NAME). Secret Names
must be static so the Approval can show the complete set before any Secret
Value is released. @disableProcessEnvInjection is mandatory.
The plugin verifies XPC protocol compatibility with the signed bridge inside
Automic Vault.app. One Approval covers the complete active Secret set for the
Varlock run. After Approval, the Node application controls those Secret Values
in its memory, helpers, child processes, and output.
Publishing
CI tests every push and pull request. Publishing a GitHub release whose tag
matches v<package.json version> publishes the package through npm trusted
publishing; no long-lived npm token is used. Configure npm's trusted publisher
for automic-vault/varlock-plugin and .github/workflows/publish.yml before the
first release.
