once is a small Go CLI that runs a command once and reuses its stdout from a per-user in-memory background daemon for a configurable time. It caches command output keyed by a tenant namespace plus working directory, command and args (directory optional with no-dir), and serves repeated calls from memory until ttl or an absolute until time expires. Common usage is avoiding repeated secret approvals (example: caching 1Password reads for hours), with commands like ttl, until, tenant, refresh, no-dir, status and clear. Only stdout is cached; stdin and stderr are forwarded, non-zero exits are never cached, and outputs above 64 MiB are passed through but not stored. Installation is via go install (Go 1.27+, macOS/Linux).
Caching uses an HMAC-SHA256 key (tenant, dir‖command‖args) computed by the client so the tenant value is not sent to the daemon. A per-user Unix socket in XDG_RUNTIME_DIR (or temp/ONCE_RUNTIME_DIR) exposes the daemon; that runtime directory is 0700 and socket 0600, so other system users cannot connect but processes of the same user can. Values live only in daemon memory (overwritten on drop), core dumps are disabled, and expiry checks use wall-clock time so sleep/resume behaves correctly. The daemon auto-starts on miss and shuts down when entries expire. License: MIT.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.