feat: add openbao-session plugin for interactive agents
SessionStart hook that provisions a short-lived, policy-scoped OpenBao token for each agent session. For Claude Code it writes export lines into $CLAUDE_ENV_FILE; for hosts that cannot persist env from hooks (Codex) it writes a mode-600 session env file and points the agent to it via context. Failure degrades to a benign JSON so sessions still start. Registered in both Claude and Codex marketplace manifests. Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
16
plugins/openbao-session/hooks/claude-codex-hooks.json
Normal file
16
plugins/openbao-session/hooks/claude-codex-hooks.json
Normal file
@@ -0,0 +1,16 @@
|
||||
{
|
||||
"hooks": {
|
||||
"SessionStart": [
|
||||
{
|
||||
"hooks": [
|
||||
{
|
||||
"type": "command",
|
||||
"command": "bash \"${CLAUDE_PLUGIN_ROOT}/hooks/bao-session.sh\"",
|
||||
"timeout": 30,
|
||||
"statusMessage": "Provisioning OpenBao session token..."
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user