77 CLOUD_SDK_CBC_URL CBC service base URL (required)
88 CLOUD_SDK_CBC_CERT_PATH Path to PEM client certificate file
99 CLOUD_SDK_CBC_KEY_PATH Path to PEM private key file
10+ CLOUD_SDK_CBC_CERT PEM client certificate value (alternative to CERT_PATH)
11+ CLOUD_SDK_CBC_KEY PEM private key value (alternative to KEY_PATH)
1012"""
1113
1214from __future__ import annotations
2022ENV_URL = "CLOUD_SDK_CBC_URL"
2123ENV_CERT_PATH = "CLOUD_SDK_CBC_CERT_PATH"
2224ENV_KEY_PATH = "CLOUD_SDK_CBC_KEY_PATH"
25+ ENV_CERT = "CLOUD_SDK_CBC_CERT"
26+ ENV_KEY = "CLOUD_SDK_CBC_KEY"
2327ENV_REPLACE_SUBDOMAIN = "CLOUD_SDK_CBC_REPLACE_SUBDOMAIN"
2428
2529
@@ -31,6 +35,8 @@ class CBCConfig:
3135 base_url: CBC service base URL.
3236 cert_path: Path to the PEM client certificate file, or ``None`` for local/mock mode.
3337 key_path: Path to the PEM private key file, or ``None`` for local/mock mode.
38+ cert_pem: PEM client certificate value. Alternative to ``cert_path``.
39+ key_pem: PEM private key value. Alternative to ``key_path``.
3440 replace_subdomain: Whether to rewrite the URL subdomain to the CBC tenant ID
3541 on each request. ``None`` (default) auto-detects: loopback URLs disable it,
3642 all others enable it. Set explicitly to ``False`` for HTTPS mock servers.
@@ -39,6 +45,8 @@ class CBCConfig:
3945 base_url : str
4046 cert_path : Path | None = None
4147 key_path : Path | None = None
48+ cert_pem : str | None = None
49+ key_pem : str | None = None
4250 replace_subdomain : bool | None = None
4351
4452
@@ -47,10 +55,13 @@ def load_from_env() -> CBCConfig:
4755
4856 Resolution order (first match wins):
4957
50- 1. **Credential triplet** — ``CLOUD_SDK_CBC_CERT_PATH``,
51- ``CLOUD_SDK_CBC_KEY_PATH``, and ``CLOUD_SDK_CBC_URL`` must all be set.
52- The path vars must point to existing PEM files.
53- 2. **URL only** — loopback addresses (``http://localhost``,
58+ 1. **Path triplet** — ``CLOUD_SDK_CBC_CERT_PATH``, ``CLOUD_SDK_CBC_KEY_PATH``,
59+ and ``CLOUD_SDK_CBC_URL`` must all be set. The path vars must point to
60+ existing PEM files.
61+ 2. **Value triplet** — ``CLOUD_SDK_CBC_CERT``, ``CLOUD_SDK_CBC_KEY``, and
62+ ``CLOUD_SDK_CBC_URL`` must all be set. PEM values are written to temp
63+ files deleted after the first connection.
64+ 3. **URL only** — loopback addresses (``http://localhost``,
5465 ``http://127.0.0.1``) trigger local/mock mode (no mTLS, no subdomain
5566 replacement). Non-loopback URLs produce a client without mTLS.
5667
@@ -63,28 +74,45 @@ def load_from_env() -> CBCConfig:
6374 path env var points to a non-existent file.
6475 """
6576 url = os .environ .get (ENV_URL )
77+ replace_subdomain = _read_env_bool (ENV_REPLACE_SUBDOMAIN )
6678
67- cert = _read_env_path (ENV_CERT_PATH )
68- key = _read_env_path (ENV_KEY_PATH )
69- if cert and key and url :
79+ cert_path = _read_env_path (ENV_CERT_PATH )
80+ key_path = _read_env_path (ENV_KEY_PATH )
81+ if cert_path and key_path and url :
7082 return CBCConfig (
7183 base_url = url ,
72- cert_path = cert ,
73- key_path = key ,
74- replace_subdomain = _read_env_bool ( ENV_REPLACE_SUBDOMAIN ) ,
84+ cert_path = cert_path ,
85+ key_path = key_path ,
86+ replace_subdomain = replace_subdomain ,
7587 )
76- if cert or key :
88+ if cert_path or key_path :
7789 raise CBCConfigError (
7890 "CBC env-var credential triplet is incomplete. "
7991 f"Set all of { ENV_CERT_PATH } , { ENV_KEY_PATH } , and { ENV_URL } — or none."
8092 )
8193
94+ cert_pem = os .environ .get (ENV_CERT )
95+ key_pem = os .environ .get (ENV_KEY )
96+ if cert_pem and key_pem and url :
97+ return CBCConfig (
98+ base_url = url ,
99+ cert_pem = cert_pem ,
100+ key_pem = key_pem ,
101+ replace_subdomain = replace_subdomain ,
102+ )
103+ if cert_pem or key_pem :
104+ raise CBCConfigError (
105+ "CBC env-var credential pair is incomplete. "
106+ f"Set both { ENV_CERT } and { ENV_KEY } together with { ENV_URL } — or none."
107+ )
108+
82109 if url :
83- return CBCConfig (base_url = url , replace_subdomain = _read_env_bool ( ENV_REPLACE_SUBDOMAIN ) )
110+ return CBCConfig (base_url = url , replace_subdomain = replace_subdomain )
84111
85112 raise CBCConfigError (
86113 f"No CBC configuration found. Set { ENV_URL } at minimum, "
87- f"or provide mTLS credentials via { ENV_CERT_PATH } / { ENV_KEY_PATH } ."
114+ f"or provide mTLS credentials via { ENV_CERT_PATH } / { ENV_KEY_PATH } "
115+ f"or { ENV_CERT } / { ENV_KEY } ."
88116 )
89117
90118
0 commit comments