roboto.domain.secrets
Submodules
Package Contents
AwsSecretRetrievalLocation
Bases: pydantic.BaseModel
Information required to retrieve a secret from AWS Secrets Manager.
Parameters
data AnyAttributes
AwsSecretRetrievalLocation.store_type
Type of secret store. Referenced here explicitly to make deserialization work better.
AwsSecretsManagerAccessCreds
Bases: pydantic.BaseModel
Context required to update a secret in AWS Secrets Manager.
Parameters
data AnyAttributes
AwsSecretsManagerAccessCreds.store_type
Type of secret store. Referenced here explicitly to make deserialization work better.
CreateSecretRequest
Bases: pydantic.BaseModel
Request payload for the Create Secret
Parameters
data AnyAttributes
GetSecretAccessCredsResponse
Bases: pydantic.BaseModel
Response payload for the Update Secret
Parameters
data AnyAttributes
GetSecretAccessCredsResponse.creds
Creds required to update the secret in its underlying data store.
GetSecretAccessCredsResponse.record
The secret whose value is going to be updated.
Secret
A secret stored in the Roboto platform’s secret management system.
Secrets provide secure storage for sensitive information like API keys, passwords, and other credentials that can be used by actions during execution. Each secret is scoped to an organization and stored in a secure backend (currently AWS Secrets Manager). The secret’s value is never sent through Roboto’s APIs, providing an additional layer of security.
Secret names are unique within an organization, so a name + org_id combination provides a fully qualified reference to a specific secret.
Secrets cannot be instantiated directly through the constructor. Use the class methods create(), from_name(), or for_org() to create or retrieve secrets.
Parameters
roboto_client roboto.Secret.create()
Create a new secret in the Roboto platform.
Creates a new secret with the specified name and optionally sets its initial value. The secret will be stored in the organization’s secure secret store (AWS Secrets Manager).
Parameters
name strName of the secret to create. Must be unique within the organization.
caller_org_id Optional[str]Organization ID where the secret should be created. If not provided, creates the secret in the caller’s organization.
initial_value Optional[str]Optional initial value to set for the secret. If provided, the secret’s value will be set immediately after creation.
roboto_client Optional[roboto.HTTP client for API communication. If not provided, uses the default client configuration.
Returns
A new Secret instance representing the created secret.
Raises
The caller is not authorized to create secrets in the specified organization.
A secret with the same name already exists in the organization.
Invalid parameters provided.
Malformed request.
Usage
Create a secret without an initial value:
secret = Secret.create(name="api_key", caller_org_id="org_123")
print(secret.name)
# 'api_key'Create a secret with an initial value:
secret = Secret.create(
name="database_password", caller_org_id="org_123", initial_value="super_secure_password"
)
print(secret.name)
# 'database_password'Secret.delete()
Delete this secret from the Roboto platform.
Permanently removes the secret and its value from the secure storage backend. This operation cannot be undone.
Raises
The caller is not authorized to delete this secret.
The secret no longer exists.
Return type
Usage
Delete a secret:
secret = Secret.from_name("old_api_key")
secret.delete()
# # Secret is now permanently deletedSecret.for_org()
Retrieve all secrets belonging to an organization.
Returns a generator that yields all secrets owned by the specified organization. Results are paginated automatically to handle large numbers of secrets efficiently.
Parameters
org_id strOrganization ID whose secrets should be retrieved.
roboto_client Optional[roboto.HTTP client for API communication. If not provided, uses the default client configuration.
Yields
Secret instances for each secret owned by the organization.
Raises
The caller is not authorized to list secrets in the specified organization.
The specified organization does not exist.
Return type
Usage
List all secrets in an organization:
secrets = list(Secret.for_org(org_id="org_123"))
for secret in secrets:
print(f"Secret: {secret.name}")
# Secret: api_key
# Secret: database_passwordProcess secrets one at a time without loading all into memory:
for secret in Secret.for_org(org_id="org_123"):
print(f"Processing secret: {secret.name}")
# Process each secret individuallySecret.from_name()
Load an existing secret by name.
Secret names are unique within an organization, so a name + org_id combination provides a fully qualified reference to a specific secret.
Parameters
name strName of the secret to retrieve. Must be unique within the organization.
org_id Optional[str]Organization ID that owns the secret. If not provided, searches in the caller’s organization.
roboto_client Optional[roboto.HTTP client for API communication. If not provided, uses the default client configuration.
Returns
A Secret instance representing the found secret.
Raises
The caller is not authorized to access the secret.
No secret with the specified name exists in the organization.
Usage
Load a secret from the caller’s organization:
secret = Secret.from_name(name="api_key")
print(secret.name)
# 'api_key'Load a secret from a specific organization:
secret = Secret.from_name(name="database_password", org_id="org_123")
print(f"{secret.name} in {secret.org_id}")
# 'database_password in org_123'Secret.from_uri()
Load an existing secret by URI.
Parameters
uri strURI of the secret to retrieve.
roboto_client Optional[roboto.HTTP client for API communication. If not provided, uses the default client configuration.
fallback_org_id Optional[str]Default organization ID to use if not provided in the URI.
Returns
A Secret instance representing the found secret.
Raises
The caller is not authorized to access the secret.
No secret with the specified name exists in the organization.
ValueErrorThe provided URI is not a valid secret URI.
Usage
Load a secret from a URI:
secret = Secret.from_uri("roboto-secret://api_key@org_123")
print(f"{secret.name} in {secret.org_id}")
# 'api_key in org_123'Load a secret from a URI with a default org ID:
secret = Secret.from_uri("roboto-secret://api_key", fallback_org_id="org_123")
print(f"{secret.name} in {secret.org_id}")
# 'api_key in org_123'Secret.read_value()
Read the value stored in this secret.
Securely retrieves the secret’s value from the underlying secret store (AWS Secrets Manager). The operation uses temporary, scoped credentials to ensure secure access to the secret store.
Returns
The secret value as a pydantic.SecretStr.
Raises
The caller is not authorized to read this secret.
The secret no longer exists.
NotImplementedErrorThe secret uses an unsupported store type.
Usage
Read a secret’s value:
secret = Secret.from_name("api_key")
value = secret.read_value()
print(value.get_secret_value())
# 'super_secret_api_key_value'Properties
Secret.record
The secret record containing metadata and configuration.
Secret.refresh()
Refresh this secret’s metadata from the Roboto platform.
Updates the secret’s local metadata by fetching the latest information from the server. This is useful to get updated timestamps or other metadata that may have changed since the secret was last loaded.
Returns
This Secret instance with updated metadata.
Raises
The caller is not authorized to access this secret.
The secret no longer exists.
Usage
Refresh a secret’s metadata:
secret = Secret.from_name("api_key")
secret.refresh()
# Secret now has the latest metadata from the serverProperties
Secret.store_type
Type of secret store backend where this secret is stored.
Currently, all secrets are stored in AWS Secrets Manager.
Secret.update_value()
Update the value stored in this secret.
Securely updates the secret’s value in the underlying secret store (AWS Secrets Manager). The operation uses temporary, scoped credentials to ensure secure access to the secret store.
Parameters
new_value strThe new value to store in the secret.
Returns
This Secret instance for method chaining.
Raises
The caller is not authorized to update this secret.
The secret no longer exists.
NotImplementedErrorThe secret uses an unsupported store type.
Usage
Update a secret’s value:
secret = Secret.from_name("api_key")
secret.update_value("new_secret_api_key_value")
# Secret value has been updated in the secure storeChain method calls:
secret = Secret.create(name="temp_key").update_value("initial_value")
print(secret.name)
# 'temp_key'Properties
Secret.uri
URI for this secret.
This URI can be used to reference the secret in other API calls.
SecretAccessCreds
Union type for all possible secret update contexts.
SecretRecord
Bases: pydantic.BaseModel
A wire-transmissible representation of a secret.
Parameters
data AnyAttributes
SecretRecord.last_used
Timestamp when the secret was last used in an action, or None if the secret has never been used.
SecretRecord.location
Information required to dereference the secret in its specific secret store. This is used in combination with temporary hyper-downscoped access creds to update or retrieve the secret’s value.
SecretStoreType
Bases: roboto.compat.StrEnum
Type of secret store.
Attributes
is_secret_uri()
Parameters
uri strReturn type