Metadata-Version: 2.5
Name: credential-vault-bridge-adapter
Version: 0.1.1
Summary: Sync Credential Vault env_file secrets into process environment
Author: Shivam Bhundiya
License: Proprietary
Keywords: dotenv,env,secrets,vault
Classifier: Development Status :: 4 - Beta
Classifier: Intended Audience :: Developers
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.10
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Python :: 3.13
Classifier: Topic :: Security
Requires-Python: >=3.10
Requires-Dist: python-dotenv>=1.0.0
Provides-Extra: dev
Requires-Dist: pytest>=8.0; extra == 'dev'
Description-Content-Type: text/markdown

# credential-vault-bridge-adapter

Python SDK to sync **Credential Vault** `env_file` secrets into your process environment on every service start.

Works with **FastAPI, Django, Flask**, Celery workers, scripts, and Docker entrypoints.

| | |
|--|--|
| **Vault website** | [https://credential-vault.darktrident.workers.dev/](https://credential-vault.darktrident.workers.dev/) |
| **API base (SDK)** | `https://credential-vault-api.onrender.com` |
| **PyPI** | `credential-vault-bridge-adapter` |
| **Requires** | Python 3.10+ |

---

## 1. Register / sign in on Credential Vault

1. Open **[Credential Vault](https://credential-vault.darktrident.workers.dev/)**.
2. **New company:** use **Register** on the home page to create your organization (you become Owner).
3. **Invited teammate:** open the invite link from your Owner, set a password, sign in.
4. Create a **project** + **environment**, then store secrets as an **`env_file`** bundle (Import .env or Create Bundle).
5. Open **Access Sheet → Injection tokens**, mint a token for that project + environment, and copy the `cvt_...` value once.

---

## 2. Install

```bash
pip install credential-vault-bridge-adapter
```

Or in `requirements.txt` / `pyproject.toml`:

```text
credential-vault-bridge-adapter>=0.1.0
```

---

## 3. Configure

Create a **gitignored** `.env` (or set platform secrets):

```bash
PROJECT_ENV_INJECTION_TOKEN=cvt_...
CREDENTIAL_VAULT_API_URL=https://credential-vault-api.onrender.com

# optional
CREDENTIAL_VAULT_WRITE_CACHE=true
CREDENTIAL_VAULT_CACHE_PATH=.env.vault
CREDENTIAL_VAULT_MAX_RETRIES=3
```

Add to `.gitignore`: `.env`, `.env.vault`

---

## 4. Load secrets before your app reads config

```python
from credential_vault_bridge_adapter import load_env

load_env()  # merges Vault keys into os.environ
```

Call this **once**, as early as possible — before Settings / pydantic / `os.getenv` for app secrets.

Framework examples and Docker entrypoints: see **`CONNECTOR.md`** in this package (also downloadable from Vault → Help).

---

## 5. CLI

```bash
credential-vault-bridge-adapter doctor
credential-vault-bridge-adapter sync
credential-vault-bridge-adapter sync --write-cache
credential-vault-bridge-adapter --version
```

`doctor` checks token, API URL, hostname header, and sync reachability.

Docker entrypoint pattern:

```sh
#!/bin/sh
set -e
export CREDENTIAL_VAULT_WRITE_CACHE="${CREDENTIAL_VAULT_WRITE_CACHE:-true}"
credential-vault-bridge-adapter sync --write-cache
set -a
. ./.env.vault
set +a
exec "$@"
```

---

## Environment variables

| Variable | Required | Description |
|----------|----------|-------------|
| `PROJECT_ENV_INJECTION_TOKEN` | yes | Injection token (`cvt_...`) from Access Sheet |
| `CREDENTIAL_VAULT_API_URL` | yes* | Vault API base — use `https://credential-vault-api.onrender.com` (*defaults to localhost only for offline lab use) |
| `CREDENTIAL_VAULT_WRITE_CACHE` | no | If `true`/`1`/`yes`, write local `.env.vault` after sync |
| `CREDENTIAL_VAULT_CACHE_PATH` | no | Cache path (default: `.env.vault`) |
| `CREDENTIAL_VAULT_MAX_RETRIES` | no | Transient 5xx/network retries (default: `3`) |

---

## Sync API

`GET {CREDENTIAL_VAULT_API_URL}/api/v1/injection/sync`

- Auth: `Authorization: Bearer <token>`
- Headers: `User-Agent`, `X-Vault-Sdk-Version`, `X-Vault-Hostname`
- Optional: `If-None-Match` → HTTP 304 when unchanged

Restart the process to pick up Vault secret changes (no background polling in v1).
