Skip to content

Add secrets management API (list/set/remove) to TinybirdClient - #33

Open
sandshoes wants to merge 1 commit into
mainfrom
tommy/protm-2265-secrets-management-api
Open

sandshoes wants to merge 1 commit into
mainfrom
tommy/protm-2265-secrets-management-api

Conversation

@sandshoes

Copy link
Copy Markdown
Contributor

Summary

  • The SDK's secret() helper only emits a {{ tb_secret(...) }} placeholder reference in datafiles — it can't manage the underlying secret value, so even an all-Python-SDK project needed tb secret set on the side.
  • Adds a client.secrets namespace (list() / set(name, value) / remove(name)) wrapping Tinybird's /v0/variables endpoint, matching tb secret ls/set/rm.
  • set() checks whether the secret exists first (GET /v0/variables/{name}) and creates (POST /v0/variables) or updates (PUT /v0/variables/{name}) accordingly — mirroring the create-or-update logic in the Forward CLI's own secret set command.
  • Verified the real endpoint contract (/v0/variables, form-encoded name/value body, variables list key) against the vendored tinybird CLI package's TinyB client (tinybird/tb/client.py) rather than guessing.

Secret-value sensitivity: list() only ever returns name/created_at/updated_at (the API itself never returns values), and the error-raising path only ever surfaces the server's error body — the value passed to set() is never interpolated into an exception message. Covered by a dedicated regression test (test_set_secret_value_never_leaks_into_error_message).

Closes https://linear.app/tinybird/issue/PROTM-2265/python-sdk-add-secrets-management-api-lssetrm

Checklist

  • CI is green (lint, typecheck, test) — secrets/gitleaks fails in this sandbox only on an unrelated SSL cert error fetching its pre-commit env
  • pre-commit run --all-files passes locally (blocked by the same sandbox SSL/network limitation, not by this change)
  • Tests were added or updated when behavior changed
  • Public API / typing changes were reviewed
  • Documentation was updated (README.md) with a "Secrets Management" section
  • Breaking changes are clearly documented (none — purely additive)
  • CHANGELOG.md was updated when user-facing behavior changed

Wraps /v0/variables so the SDK can manage the values behind the
secret() placeholder helper, matching tb secret ls/set/rm. set()
creates the secret if it doesn't exist yet, otherwise updates its
value. Secret values are never returned by list() or surfaced in
error messages.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant