feat: add openbao-session plugin for interactive agents

SessionStart hook that provisions a short-lived, policy-scoped OpenBao token
for each agent session. For Claude Code it writes export lines into
$CLAUDE_ENV_FILE; for hosts that cannot persist env from hooks (Codex) it
writes a mode-600 session env file and points the agent to it via context.
Failure degrades to a benign JSON so sessions still start. Registered in both
Claude and Codex marketplace manifests.

Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
2026-09-01 02:16:01 +07:00
parent 6693213b02
commit 5166f12775
7 changed files with 315 additions and 0 deletions

View File

@@ -7,6 +7,12 @@
"source": "./plugins/taiga-auto-sync",
"description": "Injects IT Infra & Ops Taiga tracking rules on every prompt.",
"version": "0.1.0"
},
{
"name": "openbao-session",
"source": "./plugins/openbao-session",
"description": "Provisions a short-lived OpenBao session token for interactive agents.",
"version": "0.1.0"
}
]
}