Integration

Services

A service holds the credentials one program reads: database passwords, API tokens, certificates, config values. Each field has a type, an optional environment variable name, and a change date. Use pass for logins people use and service for values software reads. fd0 stays on your admin device; it renders values for the tools you already use and installs nothing on servers or clusters.

Services need fd0 0.19.0 or later (Desktop 0.8.0). Older versions show a service as a plain secret and can delete it. Update every device that shares the scope before you add services there.

Create a service

$ fd0 service add pg-1 --scope ops --description "Postgres cluster"
$ openssl rand -base64 32 | fd0 service set pg-1 db-password - --env DB_PASSWORD
$ printf eu-central | fd0 service set pg-1 region - --type text --env REGION
$ fd0 service set pg-1 ca.crt - --type file < ca.crt
$ fd0 service set pg-1 --env-file - < app.env     # every KEY=VALUE line
$ fd0 service show pg-1

Values come only from stdin (-), never from arguments, so they do not end up in shell history or process lists. Field types are secret (default, masked in show), text (shown), and file (bytes, masked). A field keeps its type; setting the same value again records no change.

Hand values to a program

fd0 run --service <name> [--field <f>] -- <command>

Run the command with the service's env-named fields in its environment. fd0 is replaced by the command, so its exit status and signals are the command's own.

$ fd0 run --service pg-1 -- ./migrate.sh
fd0 service env <name> --format systemd-env|docker-env|sh

Print the env-named fields as an environment file. Pick the format the consumer parses; values a format cannot represent are refused instead of written wrongly.

$ fd0 service env pg-1 --format systemd-env \
    | ssh db-1 'sudo install -m 600 /dev/stdin /etc/app.env'
fd0 service k8s-secret <name> -n <namespace> --name <secret>

Print an Opaque Kubernetes Secret. Use --key FIELD=KEY to choose and rename keys; the default is every field under its own name.

$ fd0 service k8s-secret pg-1 -n app --name pg \
    --key db-password=DATABASE_PASSWORD \
  | kubectl apply --server-side --field-manager=fd0-pg-1 -f -
fd0 service get <name> <field> --raw

Print one value, for tools that read a single value. --raw omits the trailing newline. File fields are never printed to a terminal.

service env and k8s-secret refuse to print to a terminal; pipe them into the next command. That prevents accidents on screen, nothing more: anything that can run fd0 with your unlocked vault can read the values. With fd0 run, the values are readable by other processes of the same user and inherited by child processes, like any environment variable.

Change and roll back

$ openssl rand -base64 32 | fd0 service set pg-1 db-password -
$ fd0 service show pg-1          # revision and change date per field
$ fd0 service history show pg-1
$ fd0 service history restore pg-1 <seq>

fd0 changes the stored value only. Deploy the new value with the commands above, then restart or reload the program that reads it.