secrets

package
v0.1.56 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 31, 2026 License: AGPL-3.0 Imports: 9 Imported by: 0

Documentation

Overview

Package secrets provides explicit server-owned secret backends.

Index

Constants

This section is empty.

Variables

View Source
var (
	ErrNotFound        = errors.New("secret not found")
	ErrBackendRequired = errors.New("secret backend is required")
	ErrUnsupported     = errors.New("secret backend is unsupported on this platform")
)

Functions

func PoolBootstrapKey

func PoolBootstrapKey(poolName string) string

func ResourceCredentialKey

func ResourceCredentialKey(resourceID string) string

Types

type Backend

type Backend string
const (
	BackendFile    Backend = "file"
	BackendKeyring Backend = "keyring"
	BackendDPAPI   Backend = "dpapi"
)

type Config

type Config struct {
	Backend Backend
	Path    string
	Service string
}

Config selects exactly one secret backend. There is intentionally no automatic fallback: the deployment must make its storage posture explicit.

type Store

type Store interface {
	Get(context.Context, string) ([]byte, error)
	Put(context.Context, string, []byte) error
	Delete(context.Context, string) error
	Check() error
}

Store is the runtime secret contract. Keys are logical Boxy keys, never provider paths or user-visible credential values.

func Open

func Open(cfg Config) (Store, error)

Open constructs the selected backend.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL