Once: Cache CLI commands
github.com/alex0ptr
[4 comments hidden]
I first clicked this with just a mild curiosity. But as soon as I saw the 1password example. Lightning.
I try to do everything "the right way", no secrets on disk, gitops, the whole shebang. Even for my personal projects. But when working with API keys and agents it can get so frustrating. I refuse to admit to the number of times where I've told the agent "Please write the 1Password creds to .env and use .env instead because I'm tired of clicking approve on my watch 15 times for every test run."
[5 comments hidden]
$ cmake ..
$ output | grep "libssl version"[2 comments hidden]
Edit: Nope, looks like you can't. You only get the invoked command and no output.
[5 comments hidden]
Nixos does this for builds, but I've not seen it generalized to arbitrary processes.
[hidden]
[3 comments hidden]
[hidden]
And your network stack could handle things like: "hey last time you gave me 59MB with hash, 0xabcdef123455, can I give my caller a cached copy or has that changed?" ...so that while you're iterating on a bash pipeline that pulls data and transforms it, the data only gets pulled once.
Even attached peripherals like a scanner are in a position to know whether the old thing is still in there or whether a new thing has been loaded such that they only re-scan when there's a new thingy present to scan.
I love FP but having it at the OS level would be something new.
[hidden]
[2 comments hidden]
[10 comments hidden]
Uh I dont know about that one chief.
[9 comments hidden]
[3 comments hidden]
I'll take security by inconvenience over building what becomes the primary reason for a security incident.
[2 comments hidden]
[hidden]
If you have allowed an agent to access any kind of credential, you should assume it is no longer private.
[hidden]
It's not a perfect fix but it keeps secrets out of env with (so far for me) minimal inconvenience.
[2 comments hidden]
Been using this, for similar cli output catching. https://github.com/dimo414/bkt
Wondering what you think about the two, and what are the good reasons to use one vs the other? (Maybe: once is more actively developed? bkt hasn't been active for a year).
[hidden]
[7 comments hidden]
[2 comments hidden]
Not sure if there could be other interesting uses. I can’t think of one anyways.
[hidden]
I just want to avoid leaving my credentials and secrets on the filesystem.
EDIT: I use a lot of direnv / mise. So reloading credentials with different values is common.
[2 comments hidden]
[hidden]
For example, I have a script for automating the creation of PRs which fetches the available labels for a repo from github and presents them with fzf multi select. I store the labels with a TTL of a week so that I don’t have to fetch them every time and the script compares the file’s age against the desired TTL to invalidate.
I find it useful for augmenting other programs, but I’m not typically using it on the cli directly.
[hidden]
[hidden]
But I'm not running agents, I have different needs
aktau[2 comments hidden]
It was discussed in https://news.ycombinator.com/item?id=45670052 and others chimed in with their own (like bkt(1) and up(1)).
The main differences I see:
thomascountz[hidden]