tancheng33/dsh-credentials-vault
HashiCorp Vault backend for the credential seam: KV v2/v1, AppRole machine auth, per-operation reads so rotation needs no restart, and compare-and-swap writes.
Answers the case where provider keys must stay away from the agent host entirely. The shipped @deepseek-ai/dsh-credentials-local provider keeps keys in a 0600 YAML document, which the README quotes as stopping other OS users but not the model — discretion, not a boundary. This backend stores the keys in Vault instead, so rotating a key across twenty agents is one Vault write rather than twenty file edits, Vault's audit device records who read what and when, and the only secret on the host is an AppRole role id plus secret id rather than the provider key itself.
Install
⚠️ Install command not yet confirmed — check the README on GitHub for the exact command.
Compatibility
README: a HashiCorp Vault backend for the DeepSeek Harness credential seam (ctx.credentials). Provider keys live in Vault and the agent host holds at most a short-lived AppRole-issued token, so it works for headless, container and CI agents where the local credentials-local file would have to be shipped in. The README is explicit about what it does and does not protect, and publishes limitation and concurrency sections.
Details
- Repo: tancheng33/dsh-credentials-vault
- Category: Development & Runtime
- Stars: 0
- Version: Source install (no registry version asserted; repo 0★, MIT, last push 2026-08-16)
- Last push: 2026-08-16
- First seen: 2026-08-16
Recent updates
The README documents the comparison table, the configuration, the precedence rules and the rotation behaviour rather than a release-by-release table.
FAQ
- How is this different from the built-in credentials provider?
- Per the README, the built-in provider keeps keys in a 0600 file on the agent host — discretion, not a boundary — while this backend keeps them in Vault and leaves only a short-lived AppRole token on the host.
- Can I rotate a key without restarting?
- The README documents rotation without restart, and notes Vault's audit device records who read the key and when.
- How do I install it?
- The README's line names the bundle but leaves the --profile value blank and the npm name returned 404 on 2026-09-17; confirm the package source, use your own profile name, then point it at your Vault in the profile's cordis.patch.yml.