BarelyACompany.Locko
1.1.0
dotnet add package BarelyACompany.Locko --version 1.1.0
NuGet\Install-Package BarelyACompany.Locko -Version 1.1.0
<PackageReference Include="BarelyACompany.Locko" Version="1.1.0" />
<PackageVersion Include="BarelyACompany.Locko" Version="1.1.0" />
<PackageReference Include="BarelyACompany.Locko" />
paket add BarelyACompany.Locko --version 1.1.0
#r "nuget: BarelyACompany.Locko, 1.1.0"
#:package BarelyACompany.Locko@1.1.0
#addin nuget:?package=BarelyACompany.Locko&version=1.1.0
#tool nuget:?package=BarelyACompany.Locko&version=1.1.0
locko-dotnet-sdk
Official .NET SDK for Locko — a secrets and config management tool.
Fetch your runtime configuration and secrets with a single method call, using nothing but the .NET 9 BCL (System.Net.Http, System.Text.Json).
Requirements
- .NET 9.0+
Installation
dotnet add package BarelyACompany.Locko
Quick Start
You need an API key to fetch config. The API key is the one credential you must supply yourself — as a real environment variable, a CI secret, or a vault entry. It authenticates the request to Locko; it cannot come from Locko itself.
using Locko;
// LOCKO_API_KEY must already be set before this runs.
var client = LockoClient.Create(Environment.GetEnvironmentVariable("LOCKO_API_KEY")!);
IReadOnlyDictionary<string, string> config = await client.GetConfigAsync();
var connectionString = config["DATABASE_URL"];
Fetching specific subsets
IReadOnlyDictionary<string, string> secrets = await client.GetSecretsAsync(); // secret = true
IReadOnlyDictionary<string, string> variables = await client.GetVariablesAsync(); // secret = false
Injecting into environment variables (optional)
If your application framework resolves configuration from environment variables and you want Locko values picked up automatically, inject them before the framework starts:
// false = won't overwrite variables already set in the process
await client.InjectIntoEnvironmentAsync(false);
// true = force-overwrite everything
await client.InjectIntoEnvironmentAsync(true);
// then start your host...
var builder = WebApplication.CreateBuilder(args);
Custom HttpClient
var options = new LockoClientOptions
{
Timeout = TimeSpan.FromSeconds(15),
};
var client = LockoClient.Create(apiKey, options);
Or inject an entirely custom HttpClient (e.g. with a proxy or for testing):
var options = new LockoClientOptions
{
HttpClientFactory = () => new HttpClient(myCustomHandler),
};
var client = LockoClient.Create(apiKey, options);
Method Reference
LockoClient.Create(string apiKey)
Creates a new client with default options. apiKey is required and must not be null or whitespace.
LockoClient.Create(string apiKey, LockoClientOptions options)
Creates a new client with custom options.
LockoClient implements IDisposable. Dispose the instance when it is no longer needed to release the underlying socket. In long-lived applications you typically keep a single instance for the lifetime of the process.
using var client = LockoClient.Create(apiKey);
var config = await client.GetConfigAsync();
Client methods (all async)
| Method | Return type | Description |
|---|---|---|
GetConfigAsync(CancellationToken) |
Task<IReadOnlyDictionary<string, string>> |
All entries (secrets + variables) as key → value |
GetSecretsAsync(CancellationToken) |
Task<IReadOnlyDictionary<string, string>> |
Only entries where secret = true |
GetVariablesAsync(CancellationToken) |
Task<IReadOnlyDictionary<string, string>> |
Only entries where secret = false |
GetConfigEntriesAsync(CancellationToken) |
Task<IReadOnlyList<ConfigEntry>> |
Raw list of ConfigEntry objects with all fields |
InjectIntoEnvironmentAsync(bool, CancellationToken) |
Task |
Writes all entries into process environment variables |
ConfigEntry properties
| Property | Type | Description |
|---|---|---|
Key |
string |
Configuration key (e.g. DATABASE_URL) |
Value |
string |
Configuration value |
IsSecret |
bool |
true if the entry should be treated as sensitive |
LockoClientOptions properties
| Property | Type | Default | Description |
|---|---|---|---|
Timeout |
TimeSpan |
30 seconds | Request timeout (ignored when HttpClientFactory is set) |
HttpClientFactory |
Func<HttpClient>? |
null |
Optional factory for a custom HttpClient |
Error Handling
All errors surface as LockoException:
try
{
var config = await client.GetConfigAsync();
}
catch (LockoException ex)
{
Console.Error.WriteLine($"Status: {ex.StatusCode}"); // 0 if no HTTP response
Console.Error.WriteLine($"Message: {ex.Message}");
}
| Scenario | StatusCode |
|---|---|
| Invalid / missing API key | 401 / 403 |
| Server error | 5xx |
| Network / connectivity failure | 0 |
| Request timeout | 0 |
API
The SDK calls:
GET https://api-locko.barelyacompany.com/api/api-keys/config
X-API-Key: <apiKey>
Response format:
[
{ "key": "DATABASE_URL", "value": "postgres://...", "secret": false },
{ "key": "JWT_SECRET", "value": "...", "secret": true }
]
License
MIT — see LICENSE.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net9.0 is compatible. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 was computed. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net9.0
- No dependencies.
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.