Skip to content

Commit 9fea7e5

Browse files
committed
📄 opsctl 密码入口改为单个 --password(终端无回显交互输入)
--password-stdin 已移除。明文入口收敛为单个 --password:裸写在终端里提示 输入且不回显,无 TTY 时以退出码 3 + NEEDS TTY 拒绝;带值形态沿用 argv 路径 与既有警告,值以 "-" 开头时必须写成 --password=<value>。 同步 EN 与 zh-CN 的 cli/assets 与 guide/audit。
1 parent 4bd4aa3 commit 9fea7e5

4 files changed

Lines changed: 16 additions & 16 deletions

File tree

‎docs/cli/assets.md‎

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -41,21 +41,21 @@ The supported secret/reference inputs are mutually exclusive:
4141

4242
| Input | Behavior |
4343
|---|---|
44-
| `--password-stdin` | Reads plaintext from standard input without a prompt or echo. This is the recommended plaintext path. |
45-
| `--password <value>` | Accepts plaintext in argv and prints a warning because the value may be exposed in shell history, process listings, or CI logs. |
44+
| `--password` (bare) | Prompts for the plaintext in your terminal and reads it without echo. This is the recommended plaintext path. It needs an interactive terminal: without one the command exits with code 3 and a `NEEDS TTY` marker telling you to run it yourself. |
45+
| `--password <value>` | Accepts plaintext in argv and prints a warning because the value may be exposed in shell history, process listings, or CI logs. `--password=<value>` is equivalent, and is required when the value starts with `-`. |
4646
| `--credential-id <id>` | Reuses an existing compatible managed password or SSH-key credential. |
4747
| `--agent-source-id <id>` with `--agent-key-fingerprint <fingerprint>` | Selects an existing SSH Agent source and identity for SSH Agent authentication. |
4848

4949
For example:
5050

5151
```bash
52-
printf '%s\n' "$APP_PASSWORD" | \
53-
opsctl create asset --type redis --name cache \
54-
--config '{"host":"redis.internal","username":"default"}' \
55-
--password-stdin
52+
opsctl create asset --type redis --name cache \
53+
--config '{"host":"redis.internal","username":"default"}' \
54+
--password
55+
# Password: (typed in your terminal, never echoed)
5656
```
5757

58-
Plaintext supplied through `--password-stdin`, `--password`, or an accepted JSON secret field is encrypted in the asset. It does **not** create a reusable managed credential. Create managed passwords and SSH keys explicitly in the desktop key manager, then reference them with `--credential-id`.
58+
Plaintext supplied through `--password`, or an accepted JSON secret field, is encrypted in the asset. It does **not** create a reusable managed credential. Create managed passwords and SSH keys explicitly in the desktop key manager, then reference them with `--credential-id`.
5959

6060
Do not put SSH private keys or passphrases into automation configuration. Import the key in the desktop key manager and reference its credential ID. Kubernetes kubeconfig remains encrypted directly in the asset. Asset types without password authentication reject password inputs.
6161

‎docs/guide/audit.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -63,7 +63,7 @@ Audit payloads are raw by default: the audit writer stores the command, request,
6363

6464
Some producers own a narrower write-only contract. AI/opsctl `put_asset`, desktop asset changes, and external-edit metadata write explicit allowlisted projections. For asset creation and updates, password, Secret Access Key, kubeconfig, private-key, and passphrase fields are omitted from the audit request; they do not appear as placeholder values. Safe asset and credential queries likewise return narrow metadata DTOs and never expose password, private-key, passphrase, token, kubeconfig, or SSH Agent endpoint values.
6565

66-
Direct execution and approval surfaces are different boundaries. Tool input/output, command history, errors, and approval subjects preserve the content supplied to those surfaces. Do not pass secrets in commands or arguments on the assumption that Audit or the UI will redact them. Prefer managed credential references or a command's documented standard-input secret path, such as [`opsctl create asset --password-stdin`](/docs/cli/assets#passwords-and-authentication-references).
66+
Direct execution and approval surfaces are different boundaries. Tool input/output, command history, errors, and approval subjects preserve the content supplied to those surfaces. Do not pass secrets in commands or arguments on the assumption that Audit or the UI will redact them. Prefer managed credential references or a command's documented no-echo secret path, such as [a bare `opsctl create asset --password`](/docs/cli/assets#passwords-and-authentication-references), which prompts in your terminal instead of taking the value from argv.
6767

6868
## Approval Workflow
6969

‎i18n/zh-CN/docusaurus-plugin-content-docs/current/cli/assets.md‎

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -41,21 +41,21 @@ opsctl create asset \
4141

4242
| 输入 | 行为 |
4343
|---|---|
44-
| `--password-stdin` | 从标准输入读取明文,不显示提示也不回显;这是推荐的明文输入方式。 |
45-
| `--password <value>` | 从 argv 接收明文,并警告该值可能暴露在 Shell 历史、进程列表或 CI 日志中。 |
44+
| `--password`(不带值) | 在终端里提示输入明文,输入过程不回显;这是推荐的明文输入方式。它需要交互式终端,没有终端时命令以退出码 3 和 `NEEDS TTY` 标记结束,并提示你自己去终端里执行。 |
45+
| `--password <value>` | 从 argv 接收明文,并警告该值可能暴露在 Shell 历史、进程列表或 CI 日志中。`--password=<value>` 等价;值以 `-` 开头时必须用这种写法。 |
4646
| `--credential-id <id>` | 复用已有且类型兼容的托管密码或 SSH 密钥凭据。 |
4747
| `--agent-source-id <id>` 与 `--agent-key-fingerprint <fingerprint>` | 为 SSH Agent 认证选择已有 Agent 来源和身份。 |
4848

4949
例如:
5050

5151
```bash
52-
printf '%s\n' "$APP_PASSWORD" | \
53-
opsctl create asset --type redis --name cache \
54-
--config '{"host":"redis.internal","username":"default"}' \
55-
--password-stdin
52+
opsctl create asset --type redis --name cache \
53+
--config '{"host":"redis.internal","username":"default"}' \
54+
--password
55+
# 密码:(在终端里输入,不回显)
5656
```
5757

58-
通过 `--password-stdin`、`--password` 或允许的 JSON 秘密字段传入的明文会加密到资产中,**不会**隐式创建可复用的托管凭据。请先在桌面端密钥管理器中显式创建托管密码或导入 SSH 密钥,再通过 `--credential-id` 引用。
58+
通过 `--password` 或允许的 JSON 秘密字段传入的明文会加密到资产中,**不会**隐式创建可复用的托管凭据。请先在桌面端密钥管理器中显式创建托管密码或导入 SSH 密钥,再通过 `--credential-id` 引用。
5959

6060
不要把 SSH 私钥或 passphrase 放进自动化配置。应先在桌面端密钥管理器中导入密钥,再引用其凭据 ID。Kubernetes kubeconfig 仍直接加密在资产中。不使用密码认证的资产类型会拒绝密码输入。
6161

‎i18n/zh-CN/docusaurus-plugin-content-docs/current/guide/audit.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ opsctl list audit --asset web-01 --limit 50
2424

2525
审计写入默认不会扫描命令、请求、结果或错误并猜测其中的秘密;请求最多保留 4KB,结果最多保留 32KB。资产创建/更新以及安全资产/凭据查询使用窄字段投影,不写入密码、Secret Access Key、kubeconfig、私钥或 passphrase。
2626

27-
不要假设审计或 UI 会替命令参数脱敏。优先使用托管凭据引用或命令明确提供的标准输入秘密通道,例如 [`opsctl create asset --password-stdin`](/docs/cli/assets#密码与认证引用)。
27+
不要假设审计或 UI 会替命令参数脱敏。优先使用托管凭据引用或命令明确提供的无回显输入通道,例如[不带值的 `opsctl create asset --password`](/docs/cli/assets#密码与认证引用)——它在终端里提示输入,不经过 argv。
2828

2929
## opsctl 审批流程
3030

0 commit comments

Comments
 (0)