Repository navigation
LibreSeal CLI: libreseal command, no Phase Cloud default, LIBRESEAL_* variables - #1
Conversation
LIBRESEAL_HOST, LIBRESEAL_SERVICE_TOKEN, LIBRESEAL_VERIFY_SSL and friends take precedence over their PHASE_* aliases. auth always asks for the server URL, and a service token without a host is an error instead of silently targeting console.phase.dev. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…e calls The binary and root command are now 'libreseal'. 'update' prints source-build instructions instead of downloading pkg.phase.dev/install.sh, 'docs' opens the LibreSeal CLI README, and dynamic-secrets subcommands report that LibreSeal servers do not provide the feature. BREAKING CHANGE: the executable is 'libreseal'; there is no default host. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Rename PHASE.md to LIBRESEAL.md, install it as the libreseal-cli skill, require least-privilege service account tokens, warn that agent detection is defence in depth only, and add a test that every command and flag in the skill exists in the CLI. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Add scripts/install-from-source.sh, build the libreseal image and binaries, remove Phase package-manager/Docker Hub publishing workflows and the pkg.phase.dev installer, and rewrite the README. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Covers token auth, init, secrets CRUD, import/export, process injection without printing values, agent-mode guards, PHASE_* aliases, the missing default host and least-privilege denials. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ECC Tools / Security EvidenceCommit: Security scanner evidence required (action_required) Detected 1 security-sensitive predictive risk signal(s) without scanner evidence. Mode: enforce Findings:
Touched security-sensitive paths:
Expected evidence:
Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission. |
ECC Tools / PR Risk TaxonomyCommit: PR taxonomy review recommended (neutral) Detected 3 PR taxonomy bucket(s): Security Evidence, CI/CD Recommendation, Cost/Token Risk. Scanned 45 changed file(s). Roadmap taxonomy buckets: Security EvidenceSecurity-sensitive changes should carry explicit scanner, code-scanning, or focused regression evidence. Signals:
Paths:
CI/CD RecommendationCI, dependency, coverage, and contract signals should be routed into follow-up checks or verification work. Signals:
Paths:
Cost/Token RiskAI routing, usage, and token-budget changes should include budget or usage-limit evidence. Signals:
Paths:
Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission. |
|
Related PRs (verified together): server Dos2Locos/libreseal#1 · CLI #1 · skills Dos2Locos/libreseal-skills#1 |
ECC Tools / Reference Set ReadinessCommit: Reference set readiness gaps detected (neutral) Reference evidence present for 0/7 areas (0%) across 45 changed file(s). This check is based on files changed in this PR. Repository-level readiness is still reported by
Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission. |
ECC Tools / Hosted Promotion ReadinessCommit: Hosted promotion readiness passed (success) No hosted promotion evidence gaps detected across 45 changed file(s); 0 corpus scenarios had matching evidence. This check compares PR file changes against the evaluator/RAG promotion corpus in No evaluator corpus scenarios matched this PR. Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission. |
ECC Tools / PR Config AuditCommit: No changed-config issues detected (success) Scanned 1 config file(s) present at this commit across 4 changed config path(s) and found no issues in the supported security rules. Changed config files:
Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission. |
ECC Tools / PR Harness AuditCommit: No harness issues detected (success) Scanned 4 changed config file(s) and found no harness issues. Changed config files:
Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 06671ec2c9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if [ -w "$DEST" ]; then | ||
| install -m 0755 "$OUT/libreseal" "$DEST/libreseal" | ||
| else | ||
| sudo install -m 0755 "$OUT/libreseal" "$DEST/libreseal" |
There was a problem hiding this comment.
Create privileged destination directories before installing
When a requested INSTALL_DIR does not exist and its parent is not writable (for example, ./scripts/install-from-source.sh /opt/libreseal/bin as an unprivileged user), the preceding mkdir failure is ignored and this sudo install invocation still fails because install does not create missing parent directories without an option such as -D. Create the destination with elevated privileges before copying so the documented custom-install-directory path works.
Useful? React with 👍 / 👎.
LibreSeal CLI: fork of the Phase CLI adapted to self-hosted LibreSeal servers (OpenSpec change
establish-libresealin Dos2Locos/libreseal).What changes
libreseal; LibreSeal branding.LIBRESEAL_HOST,LIBRESEAL_SERVICE_TOKEN,LIBRESEAL_VERIFY_SSL,LIBRESEAL_OFFLINE… withPHASE_*accepted as aliases (LIBRESEAL_* wins).authasks for the server URL; a service token without a host is an error.updateprints source-build instructions (nopkg.phase.dev/install.sh);docsopens the LibreSeal README; dynamic-secrets commands report the feature is unavailable on LibreSeal servers.LIBRESEAL.md(least-privilege service accounts, process injection, detection is defence in depth) with a test that every documented command/flag exists.scripts/install-from-source.sh, Dockerfile/goreleaser forlibreseal, Phase publishing workflows removed, README rewritten.scripts/e2e/cli-e2e.shend-to-end test.Compatibility kept:
.phase.json,~/.phaseconfig,phase-cli-user-*keyring entries, flags, API/token formats; Go module path unchanged (github.com/phasehq/cli).Validation (executed)
go vet ./...,go test ./...pass.scripts/e2e/cli-e2e.shagainst a local LibreSeal v0.1.0 instance: 29/29 (token auth, CRUD, import/export, injection without printing values, agent-mode guards, aliases, least-privilege denials).License remains GPL-3.0. Do not merge yet — review requested.
🤖 Generated with Claude Code