Skip to content

Models

models

Value-less credential catalog models.

These pydantic models describe credential schemas only — they never hold a secret value (security invariant AC5). A :class:CredentialSpec declares where and how a credential is fetched; a :class:CredentialGroup bundles the specs a package requires.

Layer = Literal['env', 'file', 'keyring', 'default', 'prompt']

Resolution layer a credential may be sourced from.

CredentialGroup

Bases: BaseModel

A bundle of credential specs declared by a package.

Source code in packages/axm-vault/src/axm_vault/models.py
Python
class CredentialGroup(BaseModel):  # type: ignore[explicit-any]
    """A bundle of credential specs declared by a package."""

    model_config = ConfigDict(
        frozen=True,
        extra="forbid",
        arbitrary_types_allowed=True,
    )

    id: str
    package: str
    title: str
    specs: tuple[CredentialSpec, ...]
    auth_dependencies: tuple[AuthDependencySpec, ...] = ()
    multi: bool = False
    instances: InstanceSource | None = None

    def spec(self, name: str) -> CredentialSpec:
        """Return the spec named ``name``.

        Raises:
            KeyError: if no spec with that name exists in the group.
        """
        for candidate in self.specs:
            if candidate.name == name:
                return candidate
        raise KeyError(f"unknown credential {self.id}.{name!r}")
spec(name)

Return the spec named name.

Raises:

Type Description
KeyError

if no spec with that name exists in the group.

Source code in packages/axm-vault/src/axm_vault/models.py
Python
def spec(self, name: str) -> CredentialSpec:
    """Return the spec named ``name``.

    Raises:
        KeyError: if no spec with that name exists in the group.
    """
    for candidate in self.specs:
        if candidate.name == name:
            return candidate
    raise KeyError(f"unknown credential {self.id}.{name!r}")

CredentialSpec

Bases: BaseModel

Schema for a single credential — value-less by construction.

Source code in packages/axm-vault/src/axm_vault/models.py
Python
class CredentialSpec(BaseModel):  # type: ignore[explicit-any]
    """Schema for a single credential — value-less by construction."""

    model_config = ConfigDict(frozen=True, extra="forbid")

    name: str
    env: str
    kind: str
    sensitivity: Sensitivity = Sensitivity.SECRET
    required: bool = True
    default: str | None = None
    prompt: str | None = None
    aliases: tuple[str, ...] = ()

InstanceSource

Bases: Protocol

Capability supplied by packages that declare named instances.

Source code in packages/axm-vault/src/axm_vault/models.py
Python
@runtime_checkable
class InstanceSource(Protocol):
    """Capability supplied by packages that declare named instances."""

    def list_instances(self) -> Sequence[str]:
        """Return the names of currently declared instances."""
        ...

    def declare(self, instance: str) -> None:
        """Declare an instance by name."""
        ...
declare(instance)

Declare an instance by name.

Source code in packages/axm-vault/src/axm_vault/models.py
Python
def declare(self, instance: str) -> None:
    """Declare an instance by name."""
    ...
list_instances()

Return the names of currently declared instances.

Source code in packages/axm-vault/src/axm_vault/models.py
Python
def list_instances(self) -> Sequence[str]:
    """Return the names of currently declared instances."""
    ...

Sensitivity

Bases: StrEnum

Classification of how sensitive a credential value is.

Source code in packages/axm-vault/src/axm_vault/models.py
Python
class Sensitivity(StrEnum):
    """Classification of how sensitive a credential value is."""

    SECRET = "secret"  # noqa: S105 # enum label, not a password value
    CONFIG = "config"
    NONSENSITIVE = "nonsensitive"