Elinpf/dsh-ops-plugins--packages-ops-access-hub ↗★ 1
@elinpf/dsh-ops-access-hub
Standalone credential hub for the dsh ops suite: encrypted-at-rest storage, token-authenticated REST API, minimal web UI, and a YAML registry importer. Not a dsh plugin. 适合需要对运维凭据进行加密存储和 REST API 授权管理的系统管理员。
Install
This plugin has no verified bundle, or compatibility checks failed. Read the repository notes first. Read the full README ↗
README
Read the full README ↗Usage
dsh-ops-access-hub serve [--port 3090] [--host 127.0.0.1] [--data-dir ~/.dsh-ops-hub] \
[--key-file ] [--admin-token ] [--read-token ]
dsh-ops-access-hub import \
(--url --admin-token | --data-dir ) [--key-file ]
dsh-ops-access-hub token create --name --role [--expires-at ] \
(--url --admin-token | --data-dir ) [--key-file ]
dsh-ops-access-hub token list (--url --admin-token | --data-dir ) [--key-file ]
dsh-ops-access-hub token update --id [--name ] [--role ] \
[--expires-at | --clear-expires] \
(--url --admin-token | --data-dir ) [--key-file ]
dsh-ops-access-hub token revoke --id (--url --admin-token | --data-dir ) [--key-file ]
Every serve flag has an env counterpart (ACCESS_HUB_PORT, ACCESS_HUB_HOST, ACCESS_HUB_DATA_DIR, ACCESS_HUB_KEY_FILE, ACCESS_HUB_ADMIN_TOKEN, ACCESS_HUB_READ_TOKEN). Tokens left unset are generated randomly and printed exactly once on first start.
import converts an existing ops-access YAML registry: a single-line field value starting with /, ~/, ./ or ../ that points at a readable file is replaced by the file's content (relative paths resolve against the registry file's directory); everything else passes through unchanged. Push into a running hub with --url, or write the data file directly with --data-dir.
token create prints the new plaintext exactly once — hand it to its holder out of band; the hub cannot show it again. The static --admin-token is the issuing credential (and stays valid as break-glass afterwards). token update edits a live record in place and prints only the field names it changed (nothing when the patch matched the current values); token revoke is terminal, so a token that should work again gets a new one. token list marks each record active / expiring (d left) / EXPIRED / REVOKED .