SecretConfig#

pydantic model phalanx.models.secrets.SecretConfig#

Specification for an application secret.

Parameters:

data (Any) –

Show JSON schema
{
   "title": "SecretConfig",
   "description": "Specification for an application secret.",
   "type": "object",
   "properties": {
      "description": {
         "description": "Description of the secret",
         "title": "Description",
         "type": "string"
      },
      "copy": {
         "anyOf": [
            {
               "$ref": "#/$defs/SecretCopyRules"
            },
            {
               "type": "null"
            }
         ],
         "default": null,
         "description": "Rules for where the secret should be copied from",
         "title": "Copy rules"
      },
      "generate": {
         "anyOf": [
            {
               "$ref": "#/$defs/SimpleSecretGenerateRules"
            },
            {
               "$ref": "#/$defs/SourceSecretGenerateRules"
            },
            {
               "type": "null"
            }
         ],
         "default": null,
         "description": "Rules for how the secret should be generated",
         "title": "Generation rules"
      },
      "onepassword": {
         "allOf": [
            {
               "$ref": "#/$defs/SecretOnepasswordConfig"
            }
         ],
         "description": "Configuration for how the secret is stored in 1Password",
         "title": "1Password configuration"
      },
      "value": {
         "anyOf": [
            {
               "format": "password",
               "type": "string",
               "writeOnly": true
            },
            {
               "type": "null"
            }
         ],
         "default": null,
         "description": "Fixed value of secret",
         "title": "Value"
      }
   },
   "$defs": {
      "SecretCopyRules": {
         "additionalProperties": false,
         "description": "Rules for copying a secret value from another secret.",
         "properties": {
            "application": {
               "description": "Application from which the secret should be copied",
               "title": "Application",
               "type": "string"
            },
            "key": {
               "description": "Secret key from which the secret should be copied",
               "title": "Key",
               "type": "string"
            }
         },
         "required": [
            "application",
            "key"
         ],
         "title": "SecretCopyRules",
         "type": "object"
      },
      "SecretOnepasswordConfig": {
         "description": "Configuration for how a static secret is stored in 1Password.",
         "properties": {
            "encoded": {
               "default": false,
               "description": "Whether the 1Password copy of the secret is encoded in base64. 1Password doesn't support newlines in secrets, so secrets that contain significant newlines have to be encoded when storing them in 1Password. This flag indicates that this has been done, and therefore when retrieving the secret from 1Password, its base64-encoding must be undone.",
               "title": "Is base64-encoded",
               "type": "boolean"
            }
         },
         "title": "SecretOnepasswordConfig",
         "type": "object"
      },
      "SimpleSecretGenerateRules": {
         "additionalProperties": false,
         "description": "Rules for generating a secret value with no source information.",
         "properties": {
            "type": {
               "description": "Type of secret",
               "enum": [
                  "password",
                  "gafaelfawr-token",
                  "fernet-key",
                  "rsa-private-key"
               ],
               "title": "Secret type",
               "type": "string"
            }
         },
         "required": [
            "type"
         ],
         "title": "SimpleSecretGenerateRules",
         "type": "object"
      },
      "SourceSecretGenerateRules": {
         "description": "Rules for generating a secret from another secret.",
         "properties": {
            "type": {
               "description": "Type of secret",
               "enum": [
                  "bcrypt-password-hash",
                  "mtime"
               ],
               "title": "Secret type",
               "type": "string"
            },
            "source": {
               "description": "Key of secret on which this secret is based. This may only be set by secrets of type ``bcrypt-password-hash`` or ``mtime``.",
               "title": "Source key",
               "type": "string"
            }
         },
         "required": [
            "type",
            "source"
         ],
         "title": "SourceSecretGenerateRules",
         "type": "object"
      }
   },
   "additionalProperties": false,
   "required": [
      "description"
   ]
}

Config:
  • populate_by_name: bool = True

  • extra: str = forbid

Fields:
field copy_rules: SecretCopyRules | None = None (alias 'copy')#

Rules for where the secret should be copied from

field description: str [Required]#

Description of the secret

field generate: SecretGenerateRules | None = None#

Rules for how the secret should be generated

field onepassword: SecretOnepasswordConfig [Optional]#

Configuration for how the secret is stored in 1Password

field value: SecretStr | None = None#

Fixed value of secret

model_computed_fields: ClassVar[dict[str, ComputedFieldInfo]] = {}#

A dictionary of computed field names and their corresponding ComputedFieldInfo objects.