Fleet changelogs · dev.ecs0.net
rdmbair13m5-changelog-20260904-1942-fleet-credential-vault-and-agent-hooks

rdmbair13m5-changelog-20260904-1942-fleet-credential-vault-and-agent-hooks

Implemented the fleet-wide credential vault engine (cred_vault.py), universal agent hooks (agent_cred_hook.py), and access audit logging (~/.secrets/access_log.json). Deployed and verified across all six fleet Macs for Claude Code, Codex, and Antigravity.

[2026-09-04 19:42:00 EDT · rdmbair13m5]

Scope

What was built and deployed

  1. cred_vault.py (CLI: vault / cred_vault):

    • Secure credential storage: ~/.secrets/global.env (permissions 0600, directory 0700).
    • Audit ledger: ~/.secrets/access_log.json (permissions 0600).
    • Automatic regex extraction of vendor API keys (OpenAI, Anthropic, Google Gemini, GitHub, GitLab, Slack, Stripe, AWS, Hugging Face), database URIs with passwords, and assignment statements (export VAR=..., password: ..., apiKey: ...).
    • vault get <KEY>: Emits secret to stdout while logging access event (service, target API, email/user, timestamp, caller, incrementing use count).
    • vault set <KEY> <VALUE>: Atomically updates .env / global.env with dated backup.
    • vault scan: Filters pasted text, extracts credentials, saves them to the vault, masks secrets in the text, and generates guidance for the agent.
    • vault list: Formatted table showing service names, key names, masked previews (****), users, last accessed timestamp, caller, and use counts without revealing raw secrets.
    • vault exec -- <COMMAND>: Runs commands with vault secrets loaded directly into child process environment.
  2. agent_cred_hook.py:

    • Universal hook intercepting UserPromptSubmit (Claude Code & Codex), PreToolUse (Claude Code & Antigravity), and PreInvocation (Antigravity).
    • Automatically intercepts pasted credentials before they enter transcripts or command lines.
    • Stores extracted credentials into ~/.secrets/global.env immediately.
    • Injects clean agent context instructing the model on how to access the credential via source ~/.secrets/global.env or $(vault get <KEY>).
    • Redacts raw secrets from prompt strings and command executions.
  3. Fleet Deployment & Configuration (deploy_cred_hooks.zsh):

    • Deployed scripts to ~/scripts/ and symlinks to ~/bin/ on all 6 hosts.
    • Configured ~/.claude/settings.json on all 6 hosts (preserving permissions.defaultMode = bypassPermissions).
    • Configured ~/.codex/hooks.json on all 6 hosts.
    • Configured ~/.gemini/antigravity-cli/hooks.json on all 6 hosts.
    • Canonical source committed to rdmsm4x:~/dev/fleet/ops/credential-vault/ as 45e9fe3 and pushed to fleet and backup remotes.
    • Ticket FEAT-20260904-12 opened and resolved with verification evidence.

Verification evidence

How to undo