Skip to main content

secret-handling

Sterne13
Forks2
Aktualisiert3. Juli 2026 um 03:35

Discipline and procedures for the homelab-infra Fernet-encrypted secret system. Auto-loads when reading, writing, or expanding secrets via `_SecretsManager` or `from common import secrets`; when invoking `common-secret-decoder` or `common-rotate-password`; when touching `secrets.yaml`, `@secret:`/`@include:` markers, the `PASSWORD` env var, or the `SALT` env var; when editing the CI workflows that handle `MASTER_PASSWORD`; when building OpenWRT images (which bake secrets into the rootfs); when working with `conf-gen` output (post-secret-expansion configs); or when the user asks about rotating the master password, escrow, leaked-credential remediation, or workflow-artifact encryption. Read fully before suggesting any command that could read, expand, or persist a decrypted secret.

Installation

Mit Codex oder Claude installieren Kopieren Sie diesen Prompt, fügen Sie ihn in Codex, Claude oder einen anderen Assistant ein und lassen Sie die Skill-Seite prüfen und installieren.

Datei-Explorer
3 Dateien
SKILL.md
readonly