جلب الأسرار عبر أمر خارجي
Command Helper Secret Source
ما هذه الصفحة، وماذا تحتوي.
الأسرار والمفاتيح: كلمات السر ومفاتيح الخدمات التي يحتاجها Hermes ليدخل إلى حساباتك. تُحفظ في مكان واحد محمي، فلا تظهر في المحادثات ولا في الملفات التي تشاركها. القراءة نحو 3 دقائق. انتبه: لا تكتب مفتاحًا داخل محادثة ولا داخل ملف إعداد تشاركه. استعمل متغيرات البيئة أو مدير أسرار.
نتائج مأخوذة من هذه الصفحة، لا من قالب.
- تعرف ما الأسرار والمفاتيح ولماذا قد تحتاجه.
- تقرأ الجدول وتأخذ منه السطر الذي يخصّك فقط.
- تعرف الخطأ الشائع: لا تكتب مفتاحًا داخل محادثة ولا داخل ملف إعداد تشاركه. استعمل متغيرات البيئة أو مدير أسرار.
انتقل مباشرة إلى ما تحتاجه.
بلا اختصار أو حذف.
النص أدناه منقول من المصدر الرسمي بالإنجليزية حتى تبقى الأوامر والأسماء دقيقة كما هي. قبل كل قسم شرح عربي يوضّح ما بداخله.
Resolve credentials by running your own helper command at startup — any secret store with a CLI works: keepassxc-cli, secret-tool (GNOME Keyring), pass, gpg, Vaultwarden's CLI, or a script that cats a tmpfs env file. The helper prints KEY=VALUE lines on stdout; Hermes applies them through the same orchestrator as Bitwarden and 1Password, so you can enable any combination of sources simultaneously.
How it works
إعدادات تضبطها مرة وتنساها. غيّر واحدًا في كل مرة حتى تعرف أثر كل تغيير.
- You configure a helper command in
config.yaml(never in.env— the command is configuration,.envholds values). - At startup, after
.envloads, Hermes runs the helper ONCE via/bin/sh -cand parses its stdout as a dotenv blob. - The parsed keys flow through the standard precedence ladder:
.env/shell win unlessoverride_existing: true; mapped sources beat this bulk source on contested vars; first claim wins.
secrets:
command:
enabled: true
command: "cat /run/user/1000/hermes-secrets.env"
# or any vault CLI that dumps KEY=VALUE lines:
# command: "pass show hermes/env"
# command: "secret-tool lookup service hermes-env"Config
جدول مرجعي. لا تقرأه كله، ابحث عن السطر الذي يخصّك فقط.
| Key | Default | What it does |
|---|---|---|
enabled | false | Master switch. |
command | "" | Helper run via /bin/sh -c; must print KEY=VALUE lines on stdout. |
helper_timeout_seconds | 3 | Hard timeout for one helper run. Deliberately tight — the helper must be fast and NON-interactive (no unlock prompts, no touch/PIN). |
override_existing | false | Helper values overwrite .env/shell values. Off by default (unlike Bitwarden/1Password) since a local helper is not a central rotation authority. |
Security model
شرح للفكرة نفسها. اقرأه ببطء، فبقية الأقسام تبني عليه. تذكير: كلمات السر ومفاتيح الخدمات التي يحتاجها Hermes ليدخل إلى حساباتك.
- The helper command string is YOUR configuration — same trust level as the
.envfile you control. - Output is hard-capped at 1 MiB; a runaway helper can't wedge startup (process group killed on timeout).
- The helper's stderr is discarded — vault CLI diagnostics can carry secret material, so they never reach Hermes' output. Failures log structured fields only (exit code / signal / errno), never the command string.
- Whitespace-only values are treated as "no value" — a placeholder entry never flows into an Authorization header.
- POSIX-only (needs
/bin/sh). On Windows the source reports itself unconfigured and startup continues.
Failure modes
شرح للفكرة نفسها. اقرأه ببطء، فبقية الأقسام تبني عليه.
Startup is never blocked. Errors print one line plus a → remediation hint:
| Symptom | Cause | Fix |
|---|---|---|
secrets.command.command is empty | Enabled without a command | Set secrets.command.command in config.yaml |
helper command failed | Non-zero exit, timeout, spawn failure | Run the helper manually in a shell to see its real error (Hermes discards its stderr on purpose) |
helper output was not a KEY=VALUE map | Helper printed a bare value or garbage | Make the helper emit dotenv-shaped lines |
When to use this vs a plugin
شرح للفكرة نفسها. اقرأه ببطء، فبقية الأقسام تبني عليه.
The command source is the escape hatch for vaults without a bundled integration. If you find yourself wrapping a complex CLI dance in a long script, consider a proper secret-source plugin instead — plugins get caching, provenance labels, and typed config.
سؤالان إجاباتها كلها في هذه الصفحة.
كل خيار اسم حقيقي من توثيق Hermes. حتى الخيارات الخاطئة حقيقية، لكنها من صفحات أخرى.