logoalt Hacker News

alex0ptr • today at 1:52 PM • 5 replies • view on HN

Yes - but I'm out of ideas. How else support long running agents without leaving secrets in files or by default exposed in the environment. That way I get notified the first time before they ask for credentials.


Replies

stryan • today at 3:39 PM

Fnox (by jdx of mise) supports fetching secrets and caching the results either in local age encrypted files or in a background daemon (in memory only) to minimize repeated gets. The daemon is per terminal instance too I believe so you fetching a secret once doesn't store it for the whole session.

It's not a perfect fix but it keeps secrets out of env with (so far for me) minimal inconvenience.

mehackernewsacc • today at 2:08 PM

Does https://secretspec.dev/ address your use case?

➕ show 1 reply
giancarlostoro • today at 2:07 PM

The same agents that could potentially leak your secrets? I would rather not give a hacker a cached session that unlocks the keys to the kingdom.

I'll take security by inconvenience over building what becomes the primary reason for a security incident.

➕ show 1 reply
ShakataGaNai • today at 6:15 PM

I 100% love this idea and example and I very much appreciate it.

devmor • today at 2:50 PM

Don't give secrets to agents at all that you don't plan on revoking immediately after.

If you have allowed an agent to access any kind of credential, you should assume it is no longer private.