mirror of
https://github.com/enpaul/vault2vault.git
synced 2024-11-22 01:56:48 +00:00
Initial commit
This commit is contained in:
commit
97e3352f14
7
.coveragerc
Normal file
7
.coveragerc
Normal file
@ -0,0 +1,7 @@
|
|||||||
|
[run]
|
||||||
|
branch = True
|
||||||
|
|
||||||
|
[report]
|
||||||
|
exclude_lines =
|
||||||
|
\.\.\.
|
||||||
|
pass
|
109
.gitignore
vendored
Normal file
109
.gitignore
vendored
Normal file
@ -0,0 +1,109 @@
|
|||||||
|
# Byte-compiled / optimized / DLL files
|
||||||
|
__pycache__/
|
||||||
|
*.py[cod]
|
||||||
|
*$py.class
|
||||||
|
|
||||||
|
# C extensions
|
||||||
|
*.so
|
||||||
|
|
||||||
|
# Distribution / packaging
|
||||||
|
.Python
|
||||||
|
env/
|
||||||
|
build/
|
||||||
|
develop-eggs/
|
||||||
|
dist/
|
||||||
|
downloads/
|
||||||
|
eggs/
|
||||||
|
.eggs/
|
||||||
|
lib/
|
||||||
|
lib64/
|
||||||
|
parts/
|
||||||
|
sdist/
|
||||||
|
var/
|
||||||
|
wheels/
|
||||||
|
*.egg-info/
|
||||||
|
.installed.cfg
|
||||||
|
*.egg
|
||||||
|
requirements.txt
|
||||||
|
|
||||||
|
# PyInstaller
|
||||||
|
# Usually these files are written by a python script from a template
|
||||||
|
# before PyInstaller builds the exe, so as to inject date/other infos into it.
|
||||||
|
*.manifest
|
||||||
|
*.spec
|
||||||
|
|
||||||
|
# Installer logs
|
||||||
|
pip-log.txt
|
||||||
|
pip-delete-this-directory.txt
|
||||||
|
|
||||||
|
# Unit test / coverage reports
|
||||||
|
htmlcov/
|
||||||
|
.tox/
|
||||||
|
.coverage
|
||||||
|
.coverage.*
|
||||||
|
.cache
|
||||||
|
nosetests.xml
|
||||||
|
coverage.xml
|
||||||
|
*.cover
|
||||||
|
.hypothesis/
|
||||||
|
.pytest_cache/
|
||||||
|
|
||||||
|
# Translations
|
||||||
|
*.mo
|
||||||
|
*.pot
|
||||||
|
|
||||||
|
# Django stuff:
|
||||||
|
*.log
|
||||||
|
local_settings.py
|
||||||
|
|
||||||
|
# Flask stuff:
|
||||||
|
instance/
|
||||||
|
.webassets-cache
|
||||||
|
|
||||||
|
# Scrapy stuff:
|
||||||
|
.scrapy
|
||||||
|
|
||||||
|
# Sphinx documentation
|
||||||
|
docs/_build/
|
||||||
|
docs/awesome_template*.rst
|
||||||
|
docs/modules.rst
|
||||||
|
|
||||||
|
# PyBuilder
|
||||||
|
target/
|
||||||
|
|
||||||
|
# Jupyter Notebook
|
||||||
|
.ipynb_checkpoints
|
||||||
|
|
||||||
|
# pyenv
|
||||||
|
.python-version
|
||||||
|
|
||||||
|
# celery beat schedule file
|
||||||
|
celerybeat-schedule
|
||||||
|
|
||||||
|
# SageMath parsed files
|
||||||
|
*.sage.py
|
||||||
|
|
||||||
|
# dotenv
|
||||||
|
.env
|
||||||
|
|
||||||
|
# virtualenv
|
||||||
|
.venv
|
||||||
|
venv/
|
||||||
|
ENV/
|
||||||
|
|
||||||
|
# Spyder project settings
|
||||||
|
.spyderproject
|
||||||
|
.spyproject
|
||||||
|
|
||||||
|
# Rope project settings
|
||||||
|
.ropeproject
|
||||||
|
|
||||||
|
# mkdocs documentation
|
||||||
|
/site
|
||||||
|
|
||||||
|
# mypy
|
||||||
|
.mypy_cache/
|
||||||
|
|
||||||
|
# Pycharm
|
||||||
|
.idea/
|
||||||
|
.idea/vcs.xml
|
79
.pre-commit-config.yaml
Normal file
79
.pre-commit-config.yaml
Normal file
@ -0,0 +1,79 @@
|
|||||||
|
---
|
||||||
|
# All of the pre-commit hooks here actually use the `pytyhon` pre-commit language
|
||||||
|
# setting. However, for the python language setting, pre-commit will create and manage
|
||||||
|
# a cached virtual environment for each hook ID and do a bare `pip install <repo>` into
|
||||||
|
# the venv to setup the hook. This can result in conflicting dependency versions between
|
||||||
|
# the version installed to the pre-commit venv and the version installed to the Poetry
|
||||||
|
# venv specified in the lockfile.
|
||||||
|
#
|
||||||
|
# The solution is to specify `language: system` for all hooks and then install the
|
||||||
|
# required dependencies to the Poetry venv. The `system` language skips the isolated
|
||||||
|
# venv creation and looks for the entrypoint specified by the hook in the global
|
||||||
|
# environment which, if running in the Poetry venv, will find the entrypoint provided
|
||||||
|
# by the Poetry-managed dependency.
|
||||||
|
#
|
||||||
|
repos:
|
||||||
|
- repo: local
|
||||||
|
hooks:
|
||||||
|
- id: end-of-file-fixer
|
||||||
|
name: end-of-file-fixer
|
||||||
|
entry: end-of-file-fixer
|
||||||
|
language: system
|
||||||
|
types:
|
||||||
|
- text
|
||||||
|
|
||||||
|
- id: fix-encoding-pragma
|
||||||
|
name: fix-encoding-pragma
|
||||||
|
entry: fix-encoding-pragma
|
||||||
|
language: system
|
||||||
|
args:
|
||||||
|
- "--remove"
|
||||||
|
types:
|
||||||
|
- python
|
||||||
|
|
||||||
|
- id: trailing-whitespace-fixer
|
||||||
|
name: trailing-whitespace-fixer
|
||||||
|
entry: trailing-whitespace-fixer
|
||||||
|
language: system
|
||||||
|
types:
|
||||||
|
- text
|
||||||
|
|
||||||
|
- id: check-merge-conflict
|
||||||
|
name: check-merge-conflict
|
||||||
|
entry: check-merge-conflict
|
||||||
|
language: system
|
||||||
|
types:
|
||||||
|
- text
|
||||||
|
|
||||||
|
- id: reorder-python-imports
|
||||||
|
name: reorder-python-imports
|
||||||
|
entry: reorder-python-imports
|
||||||
|
language: system
|
||||||
|
args:
|
||||||
|
- "--unclassifiable-application-module=vault2vault"
|
||||||
|
types:
|
||||||
|
- python
|
||||||
|
|
||||||
|
- id: black
|
||||||
|
name: black
|
||||||
|
entry: black
|
||||||
|
language: system
|
||||||
|
types:
|
||||||
|
- python
|
||||||
|
|
||||||
|
- id: blacken-docs
|
||||||
|
name: blacken-docs
|
||||||
|
entry: blacken-docs
|
||||||
|
language: system
|
||||||
|
types:
|
||||||
|
- text
|
||||||
|
|
||||||
|
- id: mdformat
|
||||||
|
name: mdformat
|
||||||
|
entry: mdformat
|
||||||
|
language: system
|
||||||
|
args:
|
||||||
|
- "--number"
|
||||||
|
- "--wrap=90"
|
||||||
|
types:
|
||||||
|
- markdown
|
57
.pylintrc
Normal file
57
.pylintrc
Normal file
@ -0,0 +1,57 @@
|
|||||||
|
[MESSAGES CONTROL]
|
||||||
|
|
||||||
|
# Disable the message, report, category or checker with the given id(s). You
|
||||||
|
# can either give multiple identifiers separated by comma (,) or put this
|
||||||
|
# option multiple times (only on the command line, not in the configuration
|
||||||
|
# file where it should appear only once).You can also use "--disable=all" to
|
||||||
|
# disable everything first and then reenable specific checks. For example, if
|
||||||
|
# you want to run only the similarities checker, you can use "--disable=all
|
||||||
|
# --enable=similarities". If you want to run only the classes checker, but have
|
||||||
|
# no Warning level messages displayed, use"--disable=all --enable=classes
|
||||||
|
# --disable=W"
|
||||||
|
disable=logging-fstring-interpolation
|
||||||
|
,logging-format-interpolation
|
||||||
|
,logging-not-lazy
|
||||||
|
,bad-continuation
|
||||||
|
,line-too-long
|
||||||
|
,ungrouped-imports
|
||||||
|
,typecheck
|
||||||
|
,wrong-import-order
|
||||||
|
,wrong-import-position
|
||||||
|
,inconsistent-mro
|
||||||
|
|
||||||
|
|
||||||
|
[REPORTS]
|
||||||
|
|
||||||
|
# Set the output format. Available formats are text, parseable, colorized, json
|
||||||
|
# and msvs (visual studio).You can also give a reporter class, eg
|
||||||
|
# mypackage.mymodule.MyReporterClass.
|
||||||
|
output-format=colorized
|
||||||
|
|
||||||
|
|
||||||
|
[BASIC]
|
||||||
|
|
||||||
|
# Good variable names which should always be accepted, separated by a comma
|
||||||
|
good-names=_,ip,T
|
||||||
|
|
||||||
|
|
||||||
|
[MISCELLANEOUS]
|
||||||
|
# Not FIXME or TODO
|
||||||
|
notes=XXX
|
||||||
|
|
||||||
|
|
||||||
|
[SIMILARITIES]
|
||||||
|
|
||||||
|
# Ignore imports when computing similarities.
|
||||||
|
ignore-imports=yes
|
||||||
|
|
||||||
|
# Ignore function signatures when computing similarities.
|
||||||
|
ignore-signatures=yes
|
||||||
|
|
||||||
|
# Minimum lines number of a similarity.
|
||||||
|
min-similarity-lines=10
|
||||||
|
|
||||||
|
[DESIGN]
|
||||||
|
|
||||||
|
# Maximum number of arguments for function / method
|
||||||
|
max-args=7
|
115
CODE_OF_CONDUCT.md
Normal file
115
CODE_OF_CONDUCT.md
Normal file
@ -0,0 +1,115 @@
|
|||||||
|
# Contributor Covenant Code of Conduct
|
||||||
|
|
||||||
|
## Our Pledge
|
||||||
|
|
||||||
|
We as members, contributors, and leaders pledge to make participation in our community a
|
||||||
|
harassment-free experience for everyone, regardless of age, body size, visible or
|
||||||
|
invisible disability, ethnicity, sex characteristics, gender identity and expression,
|
||||||
|
level of experience, education, socio-economic status, nationality, personal appearance,
|
||||||
|
race, religion, or sexual identity and orientation.
|
||||||
|
|
||||||
|
We pledge to act and interact in ways that contribute to an open, welcoming, diverse,
|
||||||
|
inclusive, and healthy community.
|
||||||
|
|
||||||
|
## Our Standards
|
||||||
|
|
||||||
|
Examples of behavior that contributes to a positive environment for our community include:
|
||||||
|
|
||||||
|
- Demonstrating empathy and kindness toward other people
|
||||||
|
- Being respectful of differing opinions, viewpoints, and experiences
|
||||||
|
- Giving and gracefully accepting constructive feedback
|
||||||
|
- Accepting responsibility and apologizing to those affected by our mistakes, and learning
|
||||||
|
from the experience
|
||||||
|
- Focusing on what is best not just for us as individuals, but for the overall community
|
||||||
|
|
||||||
|
Examples of unacceptable behavior include:
|
||||||
|
|
||||||
|
- The use of sexualized language or imagery, and sexual attention or advances of any kind
|
||||||
|
- Trolling, insulting or derogatory comments, and personal or political attacks
|
||||||
|
- Public or private harassment
|
||||||
|
- Publishing others' private information, such as a physical or email address, without their
|
||||||
|
explicit permission
|
||||||
|
- Other conduct which could reasonably be considered inappropriate in a professional setting
|
||||||
|
|
||||||
|
## Enforcement Responsibilities
|
||||||
|
|
||||||
|
Community leaders are responsible for clarifying and enforcing our standards of acceptable
|
||||||
|
behavior and will take appropriate and fair corrective action in response to any behavior
|
||||||
|
that they deem inappropriate, threatening, offensive, or harmful.
|
||||||
|
|
||||||
|
Community leaders have the right and responsibility to remove, edit, or reject comments,
|
||||||
|
commits, code, wiki edits, issues, and other contributions that are not aligned to this
|
||||||
|
Code of Conduct, and will communicate reasons for moderation decisions when appropriate.
|
||||||
|
|
||||||
|
## Scope
|
||||||
|
|
||||||
|
This Code of Conduct applies within all community spaces, and also applies when an
|
||||||
|
individual is officially representing the community in public spaces. Examples of
|
||||||
|
representing our community include using an official e-mail address, posting via an
|
||||||
|
official social media account, or acting as an appointed representative at an online or
|
||||||
|
offline event.
|
||||||
|
|
||||||
|
## Enforcement
|
||||||
|
|
||||||
|
Instances of abusive, harassing, or otherwise unacceptable behavior may be reported to the
|
||||||
|
community leaders responsible for enforcement at \[INSERT CONTACT METHOD\]. All
|
||||||
|
complaints will be reviewed and investigated promptly and fairly.
|
||||||
|
|
||||||
|
All community leaders are obligated to respect the privacy and security of the reporter of
|
||||||
|
any incident.
|
||||||
|
|
||||||
|
## Enforcement Guidelines
|
||||||
|
|
||||||
|
Community leaders will follow these Community Impact Guidelines in determining the
|
||||||
|
consequences for any action they deem in violation of this Code of Conduct:
|
||||||
|
|
||||||
|
### 1. Correction
|
||||||
|
|
||||||
|
**Community Impact**: Use of inappropriate language or other behavior deemed
|
||||||
|
unprofessional or unwelcome in the community.
|
||||||
|
|
||||||
|
**Consequence**: A private, written warning from community leaders, providing clarity
|
||||||
|
around the nature of the violation and an explanation of why the behavior was
|
||||||
|
inappropriate. A public apology may be requested.
|
||||||
|
|
||||||
|
### 2. Warning
|
||||||
|
|
||||||
|
**Community Impact**: A violation through a single incident or series of actions.
|
||||||
|
|
||||||
|
**Consequence**: A warning with consequences for continued behavior. No interaction with
|
||||||
|
the people involved, including unsolicited interaction with those enforcing the Code of
|
||||||
|
Conduct, for a specified period of time. This includes avoiding interactions in community
|
||||||
|
spaces as well as external channels like social media. Violating these terms may lead to a
|
||||||
|
temporary or permanent ban.
|
||||||
|
|
||||||
|
### 3. Temporary Ban
|
||||||
|
|
||||||
|
**Community Impact**: A serious violation of community standards, including sustained
|
||||||
|
inappropriate behavior.
|
||||||
|
|
||||||
|
**Consequence**: A temporary ban from any sort of interaction or public communication with
|
||||||
|
the community for a specified period of time. No public or private interaction with the
|
||||||
|
people involved, including unsolicited interaction with those enforcing the Code of
|
||||||
|
Conduct, is allowed during this period. Violating these terms may lead to a permanent ban.
|
||||||
|
|
||||||
|
### 4. Permanent Ban
|
||||||
|
|
||||||
|
**Community Impact**: Demonstrating a pattern of violation of community standards,
|
||||||
|
including sustained inappropriate behavior, harassment of an individual, or aggression
|
||||||
|
toward or disparagement of classes of individuals.
|
||||||
|
|
||||||
|
**Consequence**: A permanent ban from any sort of public interaction within the community.
|
||||||
|
|
||||||
|
## Attribution
|
||||||
|
|
||||||
|
This Code of Conduct is adapted from the [Contributor Covenant][homepage], version 2.0,
|
||||||
|
available at https://www.contributor-covenant.org/version/2/0/code_of_conduct.html.
|
||||||
|
|
||||||
|
Community Impact Guidelines were inspired by [Mozilla's code of conduct
|
||||||
|
enforcement ladder](https://github.com/mozilla/diversity).
|
||||||
|
|
||||||
|
For answers to common questions about this code of conduct, see the FAQ at
|
||||||
|
https://www.contributor-covenant.org/faq. Translations are available at
|
||||||
|
https://www.contributor-covenant.org/translations.
|
||||||
|
|
||||||
|
[homepage]: https://www.contributor-covenant.org
|
12
LICENSE.md
Normal file
12
LICENSE.md
Normal file
@ -0,0 +1,12 @@
|
|||||||
|
## Copyright 2021 Ethan Paul
|
||||||
|
|
||||||
|
Permission is hereby granted, free of charge, to any person obtaining a copy of this
|
||||||
|
software and associated documentation files (the "Software"), to deal in the Software
|
||||||
|
without restriction, including without limitation the rights to use, copy, modify, merge,
|
||||||
|
publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons
|
||||||
|
to whom the Software is furnished to do so, subject to the following conditions:
|
||||||
|
|
||||||
|
The above copyright notice and this permission notice shall be included in all copies or
|
||||||
|
substantial portions of the Software.
|
||||||
|
|
||||||
|
**THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.**
|
40
Makefile
Normal file
40
Makefile
Normal file
@ -0,0 +1,40 @@
|
|||||||
|
# genly makefile
|
||||||
|
|
||||||
|
.PHONY: help
|
||||||
|
# Put it first so that "make" without argument is like "make help"
|
||||||
|
# Adapted from:
|
||||||
|
# https://marmelab.com/blog/2016/02/29/auto-documented-makefile.html
|
||||||
|
help: ## List Makefile targets
|
||||||
|
$(info Makefile documentation)
|
||||||
|
@grep -E '^[a-zA-Z_-]+:.*?## .*$$' $(MAKEFILE_LIST) | sort | awk 'BEGIN {FS = ":.*?## "}; {printf "\033[36m%-10s\033[0m %s\n", $$1, $$2}'
|
||||||
|
|
||||||
|
clean-tox:
|
||||||
|
rm --recursive --force ./.mypy_cache
|
||||||
|
rm --recursive --force ./.tox
|
||||||
|
rm --recursive --force tests/__pycache__/
|
||||||
|
rm --recursive --force .pytest_cache/
|
||||||
|
rm --force .coverage
|
||||||
|
|
||||||
|
clean-py:
|
||||||
|
rm --recursive --force ./dist
|
||||||
|
rm --recursive --force ./build
|
||||||
|
rm --recursive --force ./*.egg-info
|
||||||
|
rm --recursive --force ./**/__pycache__/
|
||||||
|
|
||||||
|
clean: clean-tox clean-py; ## Clean temp build/cache files and directories
|
||||||
|
|
||||||
|
wheel: ## Build Python binary distribution wheel package
|
||||||
|
poetry build --format wheel
|
||||||
|
|
||||||
|
source: ## Build Python source distribution package
|
||||||
|
poetry build --format sdist
|
||||||
|
|
||||||
|
test: ## Run the project testsuite(s)
|
||||||
|
poetry run tox --recreate
|
||||||
|
|
||||||
|
dev: ## Create the local dev environment
|
||||||
|
poetry install
|
||||||
|
poetry run pre-commit install
|
||||||
|
|
||||||
|
publish: test wheel source ## Build and upload to pypi (requires $PYPI_API_KEY be set)
|
||||||
|
@poetry publish --username __token__ --password $(PYPI_API_KEY)
|
5
README.md
Normal file
5
README.md
Normal file
@ -0,0 +1,5 @@
|
|||||||
|
# vault2vault
|
||||||
|
|
||||||
|
Like [`ansible-vault rekey`](https://docs.ansible.com/ansible/latest/cli/ansible-vault.html#rekey)
|
||||||
|
but works recursively on encrypted files and in-line variables
|
||||||
|
|
1976
poetry.lock
generated
Normal file
1976
poetry.lock
generated
Normal file
File diff suppressed because it is too large
Load Diff
57
pyproject.toml
Normal file
57
pyproject.toml
Normal file
@ -0,0 +1,57 @@
|
|||||||
|
[tool.poetry]
|
||||||
|
name = "vault2vault"
|
||||||
|
version = "0.0.0"
|
||||||
|
license = "MIT"
|
||||||
|
authors = ["Ethan Paul <24588726+enpaul@users.noreply.github.com>"]
|
||||||
|
description = "Recursively rekey ansible-vault encrypted files and in-line variables"
|
||||||
|
repository = "https://github.com/enpaul/vault2vault/"
|
||||||
|
packages = [
|
||||||
|
{include = "vault2vault.py"},
|
||||||
|
{include = "tests/*.py", format = "sdist"}
|
||||||
|
]
|
||||||
|
keywords = ["ansible", "vault", "playbook", "yaml", "password"]
|
||||||
|
readme = "README.md"
|
||||||
|
classifiers = [
|
||||||
|
"Development Status :: 2 - Pre-Alpha",
|
||||||
|
"Environment :: Console",
|
||||||
|
"Framework :: Ansible",
|
||||||
|
"Intended Audience :: Developers",
|
||||||
|
"Intended Audience :: Information Technology",
|
||||||
|
"Intended Audience :: Systems Administrators",
|
||||||
|
"License :: OSI Approved :: MIT License",
|
||||||
|
"Natural Language :: English",
|
||||||
|
"Operating System :: OS Independent",
|
||||||
|
"Programming Language :: Python :: 3",
|
||||||
|
"Programming Language :: Python :: 3.6",
|
||||||
|
"Programming Language :: Python :: 3.7",
|
||||||
|
"Programming Language :: Python :: 3.8",
|
||||||
|
"Programming Language :: Python :: 3.9",
|
||||||
|
"Programming Language :: Python :: Implementation :: CPython"
|
||||||
|
]
|
||||||
|
|
||||||
|
[tool.poetry.dependencies]
|
||||||
|
python = "^3.6.1"
|
||||||
|
"ruamel.yaml" = "^0.17.16"
|
||||||
|
|
||||||
|
[tool.poetry.dev-dependencies]
|
||||||
|
bandit = "^1.6.2"
|
||||||
|
black = { version = "^21.9b0", allow-prereleases = true, python = "^3.7" }
|
||||||
|
blacken-docs = "^1.8.0"
|
||||||
|
ipython = { version = "^7.18.1", python = "^3.7" }
|
||||||
|
mypy = "^0.800"
|
||||||
|
pre-commit = "^2.7.1"
|
||||||
|
pre-commit-hooks = "^3.3.0"
|
||||||
|
pylint = "^2.4.4"
|
||||||
|
pytest = "^6.0.2"
|
||||||
|
pytest-cov = "^2.10.1"
|
||||||
|
reorder-python-imports = "^2.3.5"
|
||||||
|
safety = "^1.9.0"
|
||||||
|
toml = "^0.10.1"
|
||||||
|
tox = "^3.20.0"
|
||||||
|
tox-poetry-installer = { version = "^0.8.1", extras = ["poetry"] }
|
||||||
|
mdformat = "^0.6.4"
|
||||||
|
mdformat-gfm = "^0.2"
|
||||||
|
|
||||||
|
[build-system]
|
||||||
|
requires = ["poetry-core>=1.0.0"]
|
||||||
|
build-backend = "poetry.core.masonry.api"
|
0
tests/__init__.py
Normal file
0
tests/__init__.py
Normal file
37
tests/test_metadata.py
Normal file
37
tests/test_metadata.py
Normal file
@ -0,0 +1,37 @@
|
|||||||
|
"""Ensure that the pyproject and module metadata never drift out of sync
|
||||||
|
|
||||||
|
The next best thing to having one source of truth is having a way to ensure all of your
|
||||||
|
sources of truth agree with each other.
|
||||||
|
"""
|
||||||
|
from pathlib import Path
|
||||||
|
|
||||||
|
import toml
|
||||||
|
|
||||||
|
import vault2vault
|
||||||
|
|
||||||
|
|
||||||
|
def test_metadata():
|
||||||
|
"""Test that module metadata matches pyproject poetry metadata"""
|
||||||
|
|
||||||
|
with (Path(__file__).resolve().parent / ".." / "pyproject.toml").open() as infile:
|
||||||
|
pyproject = toml.load(infile, _dict=dict)
|
||||||
|
|
||||||
|
assert pyproject["tool"]["poetry"]["name"] == vault2vault.__title__
|
||||||
|
assert pyproject["tool"]["poetry"]["version"] == vault2vault.__version__
|
||||||
|
assert pyproject["tool"]["poetry"]["license"] == vault2vault.__license__
|
||||||
|
assert pyproject["tool"]["poetry"]["description"] == vault2vault.__summary__
|
||||||
|
assert pyproject["tool"]["poetry"]["repository"] == vault2vault.__url__
|
||||||
|
assert (
|
||||||
|
all(
|
||||||
|
item in vault2vault.__authors__
|
||||||
|
for item in pyproject["tool"]["poetry"]["authors"]
|
||||||
|
)
|
||||||
|
is True
|
||||||
|
)
|
||||||
|
assert (
|
||||||
|
all(
|
||||||
|
item in pyproject["tool"]["poetry"]["authors"]
|
||||||
|
for item in vault2vault.__authors__
|
||||||
|
)
|
||||||
|
is True
|
||||||
|
)
|
63
tox.ini
Normal file
63
tox.ini
Normal file
@ -0,0 +1,63 @@
|
|||||||
|
[tox]
|
||||||
|
envlist = py36, py37, py38, py39, static, static-tests, security
|
||||||
|
isolated_build = true
|
||||||
|
skip_missing_interpreters = true
|
||||||
|
|
||||||
|
[testenv]
|
||||||
|
description = Run the tests
|
||||||
|
require_locked_deps = true
|
||||||
|
require_poetry = true
|
||||||
|
locked_deps =
|
||||||
|
pytest
|
||||||
|
pytest-cov
|
||||||
|
toml
|
||||||
|
commands =
|
||||||
|
pytest --cov vault2vault --cov-config {toxinidir}/.coveragerc --cov-report term-missing {toxinidir}/tests/
|
||||||
|
|
||||||
|
[testenv:static]
|
||||||
|
description = Static formatting and quality enforcement
|
||||||
|
basepython = python3.8
|
||||||
|
platform = linux
|
||||||
|
ignore_errors = true
|
||||||
|
locked_deps =
|
||||||
|
black
|
||||||
|
blacken-docs
|
||||||
|
mdformat
|
||||||
|
mdformat-gfm
|
||||||
|
mypy
|
||||||
|
reorder-python-imports
|
||||||
|
pre-commit
|
||||||
|
pre-commit-hooks
|
||||||
|
pylint
|
||||||
|
commands =
|
||||||
|
pre-commit run --all-files
|
||||||
|
pylint --rcfile {toxinidir}/.pylintrc {toxinidir}/vault2vault.py
|
||||||
|
mypy --ignore-missing-imports --no-strict-optional {toxinidir}/vault2vault.py
|
||||||
|
|
||||||
|
[testenv:static-tests]
|
||||||
|
description = Static formatting and quality enforcement for the tests
|
||||||
|
basepython = python3.8
|
||||||
|
platform = linux
|
||||||
|
ignore_errors = true
|
||||||
|
locked_deps =
|
||||||
|
pylint
|
||||||
|
pytest
|
||||||
|
mypy
|
||||||
|
commands =
|
||||||
|
pylint --rcfile {toxinidir}/.pylintrc {toxinidir}/tests/
|
||||||
|
mypy --ignore-missing-imports --no-strict-optional {toxinidir}/tests/
|
||||||
|
|
||||||
|
[testenv:security]
|
||||||
|
description = Security checks
|
||||||
|
basepython = python3.8
|
||||||
|
platform = linux
|
||||||
|
ignore_errors = true
|
||||||
|
locked_deps =
|
||||||
|
bandit
|
||||||
|
safety
|
||||||
|
poetry
|
||||||
|
commands =
|
||||||
|
bandit --recursive --quiet {toxinidir}/vault2vault.py
|
||||||
|
bandit --recursive --quiet --skip B101 {toxinidir}/tests/
|
||||||
|
poetry export --format requirements.txt --output {envtmpdir}/requirements.txt --without-hashes --dev
|
||||||
|
safety check --bare --file {envtmpdir}/requirements.txt
|
8
vault2vault.py
Normal file
8
vault2vault.py
Normal file
@ -0,0 +1,8 @@
|
|||||||
|
"""CLI tool for recursively rekeying ansible-vault encrypted secrets"""
|
||||||
|
|
||||||
|
__title__ = "vault2vault"
|
||||||
|
__summary__ = "Recursively rekey ansible-vault encrypted files and in-line variables"
|
||||||
|
__version__ = "0.0.0"
|
||||||
|
__url__ = "https://github.com/enpaul/vault2vault/"
|
||||||
|
__license__ = "MIT"
|
||||||
|
__authors__ = ["Ethan Paul <24588726+enpaul@users.noreply.github.com>"]
|
Loading…
Reference in New Issue
Block a user