# @litehex/vault-cli

> CLI for HashiCorp's Vault KV2 engine

Latest version **0.1.7** (published 2024-03-29) · GPL-3.0 license · 0 weekly downloads

> **Deprecated.** This package is deprecated.

## Install

```sh
npm install @litehex/vault-cli
pnpm add @litehex/vault-cli
yarn add @litehex/vault-cli
bun add @litehex/vault-cli
```

Provides the command `vault-cli`.

## Health

**Score 10/100 (F)** — status: deprecated.

Negative: deprecated.

## Facts

| | |
|---|---|
| Version | 0.1.7 |
| Published | 2024-03-29 |
| First published | 2023-11-27 |
| Weekly downloads | 0 |
| License | GPL-3.0 |
| TypeScript types | none |
| Module format | ESM |
| Dependencies | 10 |
| Unpacked size | 54 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 204 |
| Author | Shahrad Elahi |
| Maintainers | shahradelahi |
| Keywords | vault, cli, kv-v2, hashicorp, secrets |

## Links

- npm: https://www.npmjs.com/package/@litehex/vault-cli
- Repository: https://github.com/shahradelahi/vault-cli
- Homepage: https://github.com/shahradelahi/vault-cli#readme
- Issues: https://github.com/shahradelahi/vault-cli/issues
- npm.io page: https://npm.io/package/@litehex/vault-cli

## Dependencies (10)

- [ora](https://npm.io/package/ora.md) ^8.0.1
- [zod](https://npm.io/package/zod.md) ^3.22.4
- [chalk](https://npm.io/package/chalk.md) ^5.3.0
- [execa](https://npm.io/package/execa.md) ^8.0.1
- [dotenv](https://npm.io/package/dotenv.md) ^16.4.5
- [undici](https://npm.io/package/undici.md) ^6.6.2
- [prompts](https://npm.io/package/prompts.md) ^2.4.2
- [commander](https://npm.io/package/commander.md) ^12.0.0
- [@iarna/toml](https://npm.io/package/@iarna/toml.md) ^2.2.5
- [@litehex/node-vault](https://npm.io/package/@litehex/node-vault.md) 0.2.0-canary.2

## Alternatives

- [@salesforce/cli](https://npm.io/package/@salesforce/cli.md) — 389.7K weekly downloads
- [@mintlify/cli](https://npm.io/package/@mintlify/cli.md) — 208.9K weekly downloads
- [@grafana/e2e-selectors](https://npm.io/package/@grafana/e2e-selectors.md) — 128.7K weekly downloads
- [mintlify](https://npm.io/package/mintlify.md) — 112.0K weekly downloads
- [@intlayer/cli](https://npm.io/package/@intlayer/cli.md) — 22.8K weekly downloads

## Recent versions

- 0.1.7 (latest) — 2024-03-29
- 0.1.6 — 2024-02-25
- 0.1.5 — 2024-01-28
- 0.1.4 — 2023-12-23
- 0.1.2-alpha.4 — 2023-12-14
- 0.1.2-alpha.3 — 2023-12-14
- 0.1.2-alpha.2 — 2023-12-08
- 0.1.2-alpha.1 — 2023-12-08
- 0.1.2-alpha.0 — 2023-12-08
- 0.1.2 — 2023-12-07
- 0.1.1 — 2023-12-06
- 0.1.0 — 2023-11-27

## README

# Vault CLI

A minimal CLI to access your HashiCorp's Vault secrets from the command line.

### Usage

```bash
npx @litehex/vault-cli --help
# Or
bunx @litehex/vault-cli --help
```

#### Make it global

```bash
npm i -g @litehex/vault-cli
```

### make-profile

This command will create a profile in your home directory. It will be used to store your Vault's address and token.

#### Options

```txt
Usage: vault make-profile [options] <name>

Create a new vault profile

Options:
  --endpoint-url <endpoint-url>  Vault endpoint URL
  --token <vault-token>          Vault token
  --force                        Overwrite existing profile (default: false)
  -h, --help                     display help for command
```

#### Examples

```bash
# Create a new profile
vault make-profile my-profile --endpoint-url https://vault.example.com --token my-token
```

### push

This command will push a secret to your Vault.

#### Options

```txt
Usage: vault push [options] <env-file> <secrets-path>

Push an environment to Vault

Options:
  -P, --profile <name>           Name of the profile to use.
  --endpoint-url <endpoint-url>  Vault endpoint URL
  --token <vault-token>          Vault token
  --cwd <cwd>                    Current working directory (default: ".")
  --force                        Write to Vault even if the secrets are in conflict (default: false)
  -h, --help                     display help for command
```

#### Examples

```bash
# Push a .env.local file to Vault
vault push --profile my-profile .env.local secret/my-app

# Use credentials instead of a profile
vault push --endpoint-url https://vault.example.com --token my-token .env.local secret/my-app
```

### pull

This command will pull a secret from your Vault.

#### Options

```txt
Usage: vault pull [options] <secrets-path>

Pull an environment from Vault

Options:
  -P, --profile <name>             Name of the profile to use.
  --endpoint-url <endpoint-url>    Vault endpoint URL
  --token <vault-token>            Vault token
  -O, --output-file <output-path>  Path to write the environment file to
  -F, --format <format>            Format of the environment file (default: "dotenv")
  --cwd <cwd>                      Current working directory (default: ".")
  --force                          Write environment file even if it exists (default: false)
  -h, --help                       display help for command
```

#### Examples

```bash
# Pull a secret from Vault
vault pull --profile my-profile secret/my-app

# Pull a secret from Vault and save it to a .env file
vault pull --profile my-profile secret/my-app --env-path .env

# Pull a secret from Vault and add them to shell environment
vault pull --profile my-profile secret/my-app --format shell | grep -e '^export' | source /dev/stdin
```

### pipe

This command will pull and pipe secrets from your Vault to another command.

#### Options

```txt
Usage: vault pipe [options] <secrets-path> [command...]

Pull an environment from Vault and pipe it to a command

Arguments:
  secrets-path
  command                        Command to pipe to (default: [])

Options:
  -P, --profile <name>           Name of the profile to use.
  --endpoint-url <endpoint-url>  Vault endpoint URL
  --token <vault-token>          Vault token
  --cwd <cwd>                    Current working directory (default: ".")
  -h, --help                     display help for command
```

#### Examples

```bash
# Pull a secret from Vault and pipe it to a command
vault pipe --profile my-profile secret/my-app env | grep -e '^MY_APP_'

# Pull a secret from Vault and pipe it to a node script
vault pipe --profile my-profile secret/my-app "node -e 'console.log(process.env.MY_APP_SECRET)'"
```

### rm

This command will remove a path or some versions of a secret.

#### Options

```txt
Usage: vault rm [options] <secrets-path> [versions...]

Remove a secret from Vault

Arguments:
  secrets-path
  versions                       Versions to remove. By default, path will be removed (default: [])

Options:
  -P, --profile <name>           Name of the profile to use
  --endpoint-url <endpoint-url>  Vault endpoint URL
  --token <vault-token>          Vault token
  --force                        Remove the secret without confirmation (default: false)
  -h, --help                     display help for command
```

#### Examples

```bash
# Remove a path secret from Vault
vault rm --profile my-profile secret/my-app

# Remove a secret version from Vault
vault rm --profile my-profile secret/my-app 3 4
```

### Reporting Issues

If you are having trouble getting something to work with this tool or run into any problems, you can create a
new issue [GitHub Issues](https://github.com/shahradelahi/vault-cli/issues).

### License

This project is licensed under the GPL-3.0 License - see the [LICENSE](LICENSE) file for details

---
_Source: https://npm.io/package/@litehex/vault-cli · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
