Skip to content

LibreSeal CLI: libreseal command, no Phase Cloud default, LIBRESEAL_* variables - #1

Merged
temperatio merged 5 commits into
mainfrom
feat/establish-libreseal
Oct 6, 2026
Merged

temperatio merged 5 commits into
mainfrom
feat/establish-libreseal

Conversation

@temperatio

Copy link
Copy Markdown
Member

LibreSeal CLI: fork of the Phase CLI adapted to self-hosted LibreSeal servers (OpenSpec change establish-libreseal in Dos2Locos/libreseal).

What changes

  • Command and binary renamed to libreseal; LibreSeal branding.
  • LIBRESEAL_HOST, LIBRESEAL_SERVICE_TOKEN, LIBRESEAL_VERIFY_SSL, LIBRESEAL_OFFLINE… with PHASE_* accepted as aliases (LIBRESEAL_* wins).
  • Breaking: no default Phase Cloud host — auth asks for the server URL; a service token without a host is an error.
  • update prints source-build instructions (no pkg.phase.dev/install.sh); docs opens the LibreSeal README; dynamic-secrets commands report the feature is unavailable on LibreSeal servers.
  • Embedded agent skill → LIBRESEAL.md (least-privilege service accounts, process injection, detection is defence in depth) with a test that every documented command/flag exists.
  • scripts/install-from-source.sh, Dockerfile/goreleaser for libreseal, Phase publishing workflows removed, README rewritten.
  • scripts/e2e/cli-e2e.sh end-to-end test.

Compatibility kept: .phase.json, ~/.phase config, phase-cli-user-* keyring entries, flags, API/token formats; Go module path unchanged (github.com/phasehq/cli).

Validation (executed)

  • go vet ./..., go test ./... pass.
  • scripts/e2e/cli-e2e.sh against a local LibreSeal v0.1.0 instance: 29/29 (token auth, CRUD, import/export, injection without printing values, agent-mode guards, aliases, least-privilege denials).

License remains GPL-3.0. Do not merge yet — review requested.

🤖 Generated with Claude Code

temperatio and others added 5 commits October 4, 2026 23:13
LIBRESEAL_HOST, LIBRESEAL_SERVICE_TOKEN, LIBRESEAL_VERIFY_SSL and
friends take precedence over their PHASE_* aliases. auth always asks for
the server URL, and a service token without a host is an error instead
of silently targeting console.phase.dev.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…e calls

The binary and root command are now 'libreseal'. 'update' prints
source-build instructions instead of downloading pkg.phase.dev/install.sh,
'docs' opens the LibreSeal CLI README, and dynamic-secrets subcommands
report that LibreSeal servers do not provide the feature.

BREAKING CHANGE: the executable is 'libreseal'; there is no default host.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Rename PHASE.md to LIBRESEAL.md, install it as the libreseal-cli skill,
require least-privilege service account tokens, warn that agent
detection is defence in depth only, and add a test that every command
and flag in the skill exists in the CLI.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Add scripts/install-from-source.sh, build the libreseal image and
binaries, remove Phase package-manager/Docker Hub publishing workflows
and the pkg.phase.dev installer, and rewrite the README.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Covers token auth, init, secrets CRUD, import/export, process injection
without printing values, agent-mode guards, PHASE_* aliases, the
missing default host and least-privilege denials.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ecc-tools

ecc-tools Bot commented Oct 5, 2026

Copy link
Copy Markdown

ECC Tools / Security Evidence

Commit: 06671ec2c9740ee0fa364e883d8fea940ae7f8a5

Security scanner evidence required (action_required)

Detected 1 security-sensitive predictive risk signal(s) without scanner evidence.

Mode: enforce

Findings:

  • Security-sensitive changes may ship without scanner evidence: The PR touches billing, secrets, auth, webhooks, agent, or CI-sensitive surfaces without adding obvious security scanner, code scanning, or security-focused validation evidence. (1 security-sensitive paths changed; 0 security scanner or security-focused validation artifacts changed)

Touched security-sensitive paths:

  • src/cmd/auth.go

Expected evidence:

  • Security scanner, code scanning, secret scanning, dependency/security review, or focused security regression output.
  • SARIF/code-scanning upload or equivalent pass/fail gate for the changed surface.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Oct 5, 2026

Copy link
Copy Markdown

ECC Tools / PR Risk Taxonomy

Commit: 06671ec2c9740ee0fa364e883d8fea940ae7f8a5

PR taxonomy review recommended (neutral)

Detected 3 PR taxonomy bucket(s): Security Evidence, CI/CD Recommendation, Cost/Token Risk.

Scanned 45 changed file(s).

Roadmap taxonomy buckets:

Security Evidence

Security-sensitive changes should carry explicit scanner, code-scanning, or focused regression evidence.

Signals:

  • Auth or permission changes may ship without security regression coverage
  • Security-sensitive changes may ship without scanner evidence
  • 8 security-sensitive path(s) changed

Paths:

  • .github/workflows/docker.yml
  • .github/workflows/main.yml
  • .github/workflows/release.yml
  • .github/workflows/test-install-script.yml
  • src/cmd/auth.go
  • src/cmd/auth_azure.go
  • src/cmd/secrets_import.go
  • src/cmd/secrets_list.go

CI/CD Recommendation

CI, dependency, coverage, and contract signals should be routed into follow-up checks or verification work.

Signals:

  • Regression coverage may lag behind the diff
  • Runtime config changes may ship without example or template updates
  • CI workflow changes may ship without failure-mode evidence
  • Dependency or CI drift could surface after merge
  • 4 CI or workflow path(s) changed

Paths:

  • .github/workflows/docker.yml
  • .github/workflows/main.yml
  • .github/workflows/release.yml
  • .github/workflows/test-install-script.yml
  • .goreleaser.yaml
  • scripts/e2e/cli-e2e.sh
  • scripts/install-from-source.sh
  • src/cmd/ai.go

Cost/Token Risk

AI routing, usage, and token-budget changes should include budget or usage-limit evidence.

Signals:

  • 3 cost/token path(s) changed

Paths:

  • src/pkg/ai/LIBRESEAL.md
  • src/pkg/ai/PHASE.md
  • src/pkg/ai/skill.go

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@temperatio

Copy link
Copy Markdown
Member Author

Related PRs (verified together): server Dos2Locos/libreseal#1 · CLI #1 · skills Dos2Locos/libreseal-skills#1

@ecc-tools

ecc-tools Bot commented Oct 5, 2026

Copy link
Copy Markdown

ECC Tools / Reference Set Readiness

Commit: 06671ec2c9740ee0fa364e883d8fea940ae7f8a5

Reference set readiness gaps detected (neutral)

Reference evidence present for 0/7 areas (0%) across 45 changed file(s).

This check is based on files changed in this PR. Repository-level readiness is still reported by /ecc-tools analyze comments and generated manifests.

Area Status Evidence / Next Step
Deep analyzer corpus Missing Add analyzer fixture, golden, benchmark, or reference-set files that can catch analyzer regressions.
RAG/evaluator comparison Missing Add retrieval or evaluator reference-set comparison fixtures with expected ranking behavior.
PR salvage/review corpus Missing Add stale-PR, review-thread, reopen-flow, or salvage reference cases for queue cleanup automation.
Discussion triage corpus Missing Add public discussion triage fixtures, golden cases, or reference sets for informational, answered, and no-response classifications.
Harness compatibility Missing Add cross-harness, adapter-compliance, or harness-audit evidence for Claude, Codex, OpenCode, Zed, dmux, and agent surfaces.
Security evidence Missing Attach security evidence such as SBOMs, SARIF, audit reports, or AgentShield evidence packs.
CI failure-mode evidence Missing Add captured CI failure logs, dry-run fixtures, or troubleshooting docs for common workflow failure modes.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Oct 5, 2026

Copy link
Copy Markdown

ECC Tools / Hosted Promotion Readiness

Commit: 06671ec2c9740ee0fa364e883d8fea940ae7f8a5

Hosted promotion readiness passed (success)

No hosted promotion evidence gaps detected across 45 changed file(s); 0 corpus scenarios had matching evidence.

This check compares PR file changes against the evaluator/RAG promotion corpus in src/analyzers/fixtures/evaluator-rag-corpus.ts.
Hosted output scoring inspected 0 completed cached hosted job results.

No evaluator corpus scenarios matched this PR.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Oct 5, 2026

Copy link
Copy Markdown

ECC Tools / PR Config Audit

Commit: 06671ec2c9740ee0fa364e883d8fea940ae7f8a5

No changed-config issues detected (success)

Scanned 1 config file(s) present at this commit across 4 changed config path(s) and found no issues in the supported security rules.

Changed config files:

  • .github/workflows/docker.yml
  • .github/workflows/main.yml
  • .github/workflows/release.yml
  • .github/workflows/test-install-script.yml

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Oct 5, 2026

Copy link
Copy Markdown

ECC Tools / PR Harness Audit

Commit: 06671ec2c9740ee0fa364e883d8fea940ae7f8a5

No harness issues detected (success)

Scanned 4 changed config file(s) and found no harness issues.

Changed config files:

  • .github/workflows/docker.yml
  • .github/workflows/main.yml
  • .github/workflows/release.yml
  • .github/workflows/test-install-script.yml

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 06671ec2c9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

if [ -w "$DEST" ]; then
install -m 0755 "$OUT/libreseal" "$DEST/libreseal"
else
sudo install -m 0755 "$OUT/libreseal" "$DEST/libreseal"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Create privileged destination directories before installing

When a requested INSTALL_DIR does not exist and its parent is not writable (for example, ./scripts/install-from-source.sh /opt/libreseal/bin as an unprivileged user), the preceding mkdir failure is ignored and this sudo install invocation still fails because install does not create missing parent directories without an option such as -D. Create the destination with elevated privileges before copying so the documented custom-install-directory path works.

Useful? React with 👍 / 👎.

@temperatio
temperatio merged commit f77da34 into main Oct 6, 2026
7 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant