Download the PHP package bitcoinmatex/vault-to-config without Composer
On this page you can find all versions of the php package bitcoinmatex/vault-to-config. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download bitcoinmatex/vault-to-config
More information about bitcoinmatex/vault-to-config
Files in bitcoinmatex/vault-to-config
Package vault-to-config
Short Description Nette CLI app: renders a Latte configuration template using secrets from HashiCorp Vault and generates NEON for deployment.
License BSD-3-Clause GPL-2.0-only GPL-3.0-only
Informations about the package vault-to-config
VaultToConfig
A CLI tool (a classic Nette application: Bootstrap + DI container, Latte, Symfony Console) that:
- reads secrets from HashiCorp Vault based on the environment (HTTP API, KV v1/v2),
- injects them as variables into a Latte template,
- validates the output as NEON and writes e.g.
local.neonfor deploying any Nette application.
Download
Usage
For example:
Environment variables
| Variable | Default | Meaning |
|---|---|---|
VAULT_TOKEN |
(required) | Vault token (X-Vault-Token). Not logged. |
VAULT_ADDR |
https://127.0.0.1:8200 |
Vault address. |
VAULT_KV_MOUNT |
secret |
KV mount. |
VAULT_KV_VERSION |
2 |
KV engine version (1 or 2). |
VAULT_SECRET_PATH |
{env} |
Path template under the mount; {env} = 1st arg. |
VAULT_NAMESPACE |
(optional) | Vault Enterprise namespace. |
Each one also has a flag: --vault-addr, --mount, --kv-version, --secret-path.
Path and layering
The path is relative to under the mount (the client inserts /data/ for KV v2 itself).
{env} is replaced by the environment. You can merge multiple comma-separated paths
(later ones override earlier):
Latte template
The template starts with {contentType text} (if missing, it is added automatically -> no HTML
escaping). Available variables:
{$environment}- the environment,{$vault['key']}- any key (even with dashes),{$key}- shorthand, if the name is a valid PHP identifier,- the
|neonfilter - safely encodes the value as a NEON scalar (quotes + escaping). It is recommended for all values from Vault:password: {$db_password|neon}.
Security / compliance
- Secret values are never logged - verbose (
-v) prints only the key names. (DORA art. 9/11 - audit trail without sensitive data.) - The output has
0640permissions and is in.gitignore; delete it after deploy on CI. - NEON is validated before writing - a template error never reaches production.
- Diagnostics go to stderr, the payload (
--dry-run) to stdout.
All versions of vault-to-config with dependencies
ext-json Version *
nette/bootstrap Version ^3.2
nette/robot-loader Version ^4.0
nette/neon Version ^3.4
tracy/tracy Version ^2.10
latte/latte Version ^3.0
symfony/console Version ^6.4
symfony/http-client Version ^6.4