feat(vault-tui): implement KV client and service for managing secrets

- Added internal/vault/client.go for creating a Vault client with configuration settings.
- Introduced internal/vault/errors.go to classify Vault API errors for better UI handling.
- Created internal/vault/kv.go to manage KV secrets, including listing, reading, writing, and deleting operations.
- Implemented internal/vault/mounts.go to list and describe secret engine mounts.
- Developed internal/vault/service.go to provide a unified entry point for Vault operations.
- Added internal/vault/kv_test.go for comprehensive testing of KV operations.
- Introduced internal/ui/toast.go for transient notifications in the UI.
- Added renovate.json for dependency management and updates.
This commit is contained in:
2026-08-14 11:09:03 +02:00
commit ae30ba1240
85 changed files with 9413 additions and 0 deletions
+51
View File
@@ -0,0 +1,51 @@
package token
import (
"context"
"fmt"
"github.com/hashicorp/vault/api/cliconfig"
"github.com/hashicorp/vault/api/tokenhelper"
)
// vaultCLIStore delegates to the exact packages the Vault CLI itself uses,
// so ~/.vault-token stays byte-compatible and any token_helper configured in
// ~/.vault (HCL file, overridable via VAULT_CONFIG_PATH) is honoured. Both
// api/cliconfig and api/tokenhelper ship inside the api module we already
// depend on, so this costs zero additional dependencies.
type vaultCLIStore struct {
h tokenhelper.TokenHelper
}
// NewVaultCLIStore resolves the configured token helper (falling back to
// the internal ~/.vault-token helper when none is configured).
func NewVaultCLIStore() (Store, error) {
h, err := cliconfig.DefaultTokenHelper()
if err != nil {
return nil, fmt.Errorf("resolving vault token helper: %w", err)
}
return vaultCLIStore{h: h}, nil
}
func (s vaultCLIStore) Kind() string { return "vault-cli" }
// Location calls Get first: InternalTokenHelper.Path() is only populated
// after its first Get/Store/Erase call (it lazily resolves the home
// directory internally), so an unconditional Path() call before any other
// operation would return "".
func (s vaultCLIStore) Location() string {
_, _ = s.h.Get()
return s.h.Path()
}
func (s vaultCLIStore) Get(context.Context) (string, error) {
return s.h.Get()
}
func (s vaultCLIStore) Store(_ context.Context, tok string) error {
return s.h.Store(tok)
}
func (s vaultCLIStore) Erase(context.Context) error {
return s.h.Erase()
}