- memo doesn't need to be built (its a shell script)
- once keeps output cache in a running daemon. By contrast, memo stores content under /tmp with whatever the best compression available is (it prefers zstd). There's trade-offs in that. More pareto-optimal from the security front may be to have a sort of session key and to compress-then-encrypt files on disk.
thomascountz 1 days ago [-]
Hey! I use your shell script after seeing it on HN awhile ago. It's very handy (I find myself reaching for it as if it's a built-in) and I appreciate its design (I learned a few things reading it)!
ShakataGaNai 1 days ago [-]
OMG. `op read` with agents. Holy shit.
I first clicked this with just a mild curiosity. But as soon as I saw the 1password example. Lightning.
I try to do everything "the right way", no secrets on disk, gitops, the whole shebang. Even for my personal projects. But when working with API keys and agents it can get so frustrating. I refuse to admit to the number of times where I've told the agent "Please write the 1Password creds to .env and use .env instead because I'm tired of clicking approve on my watch 15 times for every test run."
alex0ptr 23 hours ago [-]
A brother from another mother. I was afraid no one has similar workflows. :)
sharts 12 hours ago [-]
or just use fnox with caching
alex0ptr 9 hours ago [-]
Yes fnox looks great. It seems the cache is directory based here and not session based. Not sure if I like that. If my agent starts to snoop around he might use other caches transparently.
xuhu 1 days ago [-]
I wish this worked without prefixing the commands with "once". Especially if I ran a command with verbose output and afterwards decided I wanted to grep something from it. Terminals have the output in their scrollback buffer and maybe it's just a matter of writing an "output" command that lets me run:
$ cmake ..
$ output | grep "libssl version"
jiehong 11 hours ago [-]
Maybe the shell or the terminal itself could do that.
Some terminals already allow you to search they buffer after commands have executed, so maybe it’s a small step away from being able to use that as a cache.
ctippett 1 days ago [-]
You could probably achieve something like that using Fish shell and their fish_preexec and fish_postexec event hooks.
Edit: Nope, looks like you can't. You only get the invoked command and no output.
stirfish 1 days ago [-]
Could you use preexec + tee?
ctippett 7 hours ago [-]
Unfortunately not, the preexec event happens asynchronously from the actual execution of the command. You can't manipulate or otherwise log the output of what's run, all you get is a copy of the command text.
lelanthran 1 days ago [-]
I run bash from inside vim and nvim. At anytime I can drop into vim and use the entire scrolled history as a buffer.
__MatrixMan__ 1 days ago [-]
I dream of applications that expose sufficient metadata about their outputs such that the OS can know if rerunning is necessary without me needing to specify.
Nixos does this for builds, but I've not seen it generalized to arbitrary processes.
jchw 1 days ago [-]
You can, in many cases, mangle other use cases into the Nix build system, to varying degrees of success, though there are plenty of complexities with that.
jedbrooke 1 days ago [-]
this is kind of the idea behind functional programming. A pure function is one whose output depends only on its input, and no other hidden state, so that let’s you just cache a lut of input -> output for anything you’ve computed before. The tricky thing is anything that reads/writes to memory/disk/network etc. is no longer a pure function and can’t be cached easily
__MatrixMan__ 1 days ago [-]
Seems like your filesystem could keep track of whether the depended-on bits have changed and invalidate a cache if they did.
And your network stack could handle things like: "hey last time you gave me 59MB with hash, 0xabcdef123455, can I give my caller a cached copy or has that changed?" ...so that while you're iterating on a bash pipeline that pulls data and transforms it, the data only gets pulled once.
Even attached peripherals like a scanner are in a position to know whether the old thing is still in there or whether a new thing has been loaded such that they only re-scan when there's a new thingy present to scan.
I love FP but having it at the OS level would be something new.
PinkSheep 1 days ago [-]
...unless you marry it to a CoW fs that can let it travel back in time :)
ashkankiani 11 hours ago [-]
I have had my own version of this for about a decade, but the "disable coredumps to disallow leaking secrets" idea is a good one. I'm mostly using bwrap for things these days with my own wrapper, but I never thought about if bwrap can leak a coredump. Although I guess without access to the coredumps it's not a big deal.
deadbunny 1 days ago [-]
I've always wanted to deal with cache invalidation in my terminal.
_doctor_love 1 days ago [-]
Call it "memoized CLI" instead, you'll sound super cool
Wondering what you think about the two, and what are the good reasons to use one vs the other?
(Maybe: once is more actively developed? bkt hasn't been active for a year).
alex0ptr 24 hours ago [-]
Wow this is incredibly similar. I guess it seems that the notable difference is that the cached results are written to a directory - which is exactly what I wanted to avoid. So depends on what you want to cache I guess.
giancarlostoro 1 days ago [-]
> The typical use case: reading secrets from 1Password without approving every single read with your fingerprint.
Uh I dont know about that one chief.
alex0ptr 1 days ago [-]
Yes - but I'm out of ideas. How else support long running agents without leaving secrets in files or by default exposed in the environment. That way I get notified the first time before they ask for credentials.
stryan 1 days ago [-]
Fnox (by jdx of mise) supports fetching secrets and caching the results either in local age encrypted files or in a background daemon (in memory only) to minimize repeated gets. The daemon is per terminal instance too I believe so you fetching a secret once doesn't store it for the whole session.
It's not a perfect fix but it keeps secrets out of env with (so far for me) minimal inconvenience.
That looks pretty cool - even supports caching. Will take a deeper look. Thx
giancarlostoro 1 days ago [-]
The same agents that could potentially leak your secrets? I would rather not give a hacker a cached session that unlocks the keys to the kingdom.
I'll take security by inconvenience over building what becomes the primary reason for a security incident.
alex0ptr 1 days ago [-]
If I already approved it once I already have to assume it could have been leaked. The cache doesn't change much about it if the agent / tenant is asking for something it already has.
giancarlostoro 23 hours ago [-]
It slightly opens what should be a really short and brief window of access.
ShakataGaNai 1 days ago [-]
I 100% love this idea and example and I very much appreciate it.
devmor 1 days ago [-]
Don't give secrets to agents at all that you don't plan on revoking immediately after.
If you have allowed an agent to access any kind of credential, you should assume it is no longer private.
baquero 1 days ago [-]
Do you have CLI calls that you want to cache? Here you go!
stingraycharles 1 days ago [-]
Seems well-designed, but what’s the use case? I’m trying to think of them but my creativity is failing me.
adregan 1 days ago [-]
I have a small fish function that does something similar. It saves output to a file in XDG_CACHE_HOME. I wouldn’t use it for sensitive items like passwords or tokens in the examples, but I do use it for scripts that need to fetch some data from the network.
For example, I have a script for automating the creation of PRs which fetches the available labels for a repo from github and presents them with fzf multi select. I store the labels with a TTL of a week so that I don’t have to fetch them every time and the script compares the file’s age against the desired TTL to invalidate.
I find it useful for augmenting other programs, but I’m not typically using it on the cli directly.
frizlab 1 days ago [-]
From the example in the Readme, I guess retrieving a token from an API, using a secret fetched from a secure vault that requests a password or TouchID validation.
Not sure if there could be other interesting uses. I can’t think of one anyways.
alex0ptr 1 days ago [-]
Yes, exactly. This is especially frustrating when I leave an agent running for a long time and it gets stuck on my build scripts because it's waiting for my approval.
I just want to avoid leaving my credentials and secrets on the filesystem.
EDIT: I use a lot of direnv / mise. So reloading credentials with different values is common.
whilenot-dev 1 days ago [-]
I have the same question, especially since any CLI output can be stored explicitly in some variable or temp file. What's the advantage of storing the output implicitly?
alex0ptr 1 days ago [-]
I don't want to store them in a file since I don't trust my agents with that data. Instead, the daemon secures the values using/under an HMAC key, making them virtually impossible to guess.
sleepybrett 22 hours ago [-]
I might use this when i make massive `kubectl get -o json` calls to store the output so i can noodle with some jq i'm using to filter it. Right now it looks like OUTPUT=$(kubectl... -o json); echo $OUTPUT | jq '.blahblahblah' .. this seems like it might be more useful and if i'm working so long my ttl expires it will refetch say every 2m.. if i'm reading this properly.
1vuio0pswjnm7 1 days ago [-]
I just use tmux buffers
But I'm not running agents, I have different needs
newadays 1 days ago [-]
Congratulations. What is Word Error Rate? We have a few use cases for something like that at newcare.app
It was discussed in https://news.ycombinator.com/item?id=45670052 and others chimed in with their own (like bkt(1) and up(1)).
The main differences I see:
I first clicked this with just a mild curiosity. But as soon as I saw the 1password example. Lightning.
I try to do everything "the right way", no secrets on disk, gitops, the whole shebang. Even for my personal projects. But when working with API keys and agents it can get so frustrating. I refuse to admit to the number of times where I've told the agent "Please write the 1Password creds to .env and use .env instead because I'm tired of clicking approve on my watch 15 times for every test run."
Some terminals already allow you to search they buffer after commands have executed, so maybe it’s a small step away from being able to use that as a cache.
Edit: Nope, looks like you can't. You only get the invoked command and no output.
Nixos does this for builds, but I've not seen it generalized to arbitrary processes.
And your network stack could handle things like: "hey last time you gave me 59MB with hash, 0xabcdef123455, can I give my caller a cached copy or has that changed?" ...so that while you're iterating on a bash pipeline that pulls data and transforms it, the data only gets pulled once.
Even attached peripherals like a scanner are in a position to know whether the old thing is still in there or whether a new thing has been loaded such that they only re-scan when there's a new thingy present to scan.
I love FP but having it at the OS level would be something new.
Been using this, for similar cli output catching. https://github.com/dimo414/bkt
Wondering what you think about the two, and what are the good reasons to use one vs the other? (Maybe: once is more actively developed? bkt hasn't been active for a year).
Uh I dont know about that one chief.
It's not a perfect fix but it keeps secrets out of env with (so far for me) minimal inconvenience.
I'll take security by inconvenience over building what becomes the primary reason for a security incident.
If you have allowed an agent to access any kind of credential, you should assume it is no longer private.
For example, I have a script for automating the creation of PRs which fetches the available labels for a repo from github and presents them with fzf multi select. I store the labels with a TTL of a week so that I don’t have to fetch them every time and the script compares the file’s age against the desired TTL to invalidate.
I find it useful for augmenting other programs, but I’m not typically using it on the cli directly.
Not sure if there could be other interesting uses. I can’t think of one anyways.
I just want to avoid leaving my credentials and secrets on the filesystem.
EDIT: I use a lot of direnv / mise. So reloading credentials with different values is common.
But I'm not running agents, I have different needs