Once 是一款开源命令行工具,可将命令执行结果缓存在后台守护进程中 1。该工具适用于 macOS 和 Linux 系统,依赖 Go 1.27 及以上版本,无额外依赖 1。用户可通过 go install github.com/alex0ptr/once@latest 进行安装 1。
该工具的核心功能是在设定时间内缓存命令输出,重复调用相同命令时直接返回缓存结果,无需重新执行 1。缓存键采用 HMAC-SHA256 算法,基于租户、工作目录、命令及参数生成 1。用户可通过 --ttl 参数设定缓存持续时间,通过 --until 设定绝对过期时间,或使用 --no-dir 忽略工作目录作为缓存键的一部分 1。
Once 的一个典型应用场景是从 1Password 读取密钥:首次调用需指纹认证,后续调用在缓存期内无需重复验证 1。例如用户可通过命令 export GITHUB_TOKEN="$(once --ttl 8h --no-dir -- op read op://Private/GitHub/token)" 获取并缓存 GitHub 令牌 1。
在安全设计上,该工具通过 Unix socket(权限设置为 0600)和运行目录(权限设置为 0700)防止其他用户访问缓存内容,同一用户的不同进程可共享缓存 1。此外,超过 64 MiB 的命令输出将被透传但不会被缓存 1。
Once is an open-source command-line tool that executes commands and caches their output in a background daemon process, returning cached results for repeated invocations within a specified time window rather than re-executing the command1. The tool is particularly useful for scenarios like retrieving secrets from 1Password, where initial calls require fingerprint authentication but subsequent calls within the cache period bypass this verification step1.
The caching mechanism employs HMAC-SHA256 hashing of the tenant identifier, working directory, command, and parameters to generate cache keys1. Users can configure cache behavior through several parameters: --ttl sets the duration for which results remain cached, --until specifies an absolute expiration time, and --no-dir excludes the working directory from the cache key calculation1. A typical use case involves environment variable assignment: export GITHUB_TOKEN="$(once --ttl 8h --no-dir -- op read op://Private/GitHub/token)"1.
The tool runs on macOS and Linux with Go 1.27 or later and has no external dependencies1. Installation is straightforward via the command go install github.com/alex0ptr/once@latest1. Security is enforced through Unix socket permissions (0600) and run directory permissions (0700) to prevent unauthorized access by other users, though processes belonging to the same user can share cached results1. Notably, outputs exceeding 64 MiB are passed through transparently but are not cached1.
评论
还没有评论,欢迎留下第一条。