Metadata
- Status: backlog
- Phase: 4-Extensibility
- Version: v0.4.0
- Priority: medium
- Estimation: M
Description
Support encrypted environment variables and secrets. Allow storing sensitive values in encrypted form in configuration. Decrypt at runtime using a master key. Prevent accidental exposure in logs and outputs.
Acceptance Criteria
Dependencies
- Blocked by: F006
- Unblocks: none
Impacted Files
pkg/crypto/encrypt.go
pkg/crypto/decrypt.go
internal/interfaces/cli/commands/encrypt.go
internal/application/secret_manager.go
configs/secrets.yaml.enc
Technical Tasks
Notes
Usage flow:
# Encrypt a secret
echo -n "my-api-key" | awf encrypt --key-file ~/.awf/master.key
# Output: ENC[1:abc123:xyz789:encrypted_data_here]
# Store in secrets.yaml
secrets:
API_KEY: "ENC[1:abc123:xyz789:encrypted_data_here]"
# Use in workflow
command: "curl -H 'Authorization: {{secrets.API_KEY}}' api.example.com"
Master key should be at least 32 bytes. Never store in repository.
Synced from docs/plans/features/v0.4.0/F018-encrypted-env.md
Metadata
Description
Support encrypted environment variables and secrets. Allow storing sensitive values in encrypted form in configuration. Decrypt at runtime using a master key. Prevent accidental exposure in logs and outputs.
Acceptance Criteria
awf encryptcommand to encrypt valuesDependencies
Impacted Files
Technical Tasks
encryptcommandENC[version:salt:nonce:ciphertext]{{secrets.API_KEY}}Notes
Usage flow:
Master key should be at least 32 bytes. Never store in repository.
Synced from
docs/plans/features/v0.4.0/F018-encrypted-env.md