pub struct MemoryKeyRing { /* private fields */ }Expand description
A key ring in this process. For tests.
It holds the wrapping keys beside the data they protect, so it protects that data from nobody: anyone who can read the ciphertext can read the keys. What it does model faithfully is the shape a real service has — a named wrapping key per scope, a fresh data key per call, and erasure by destroying the wrapping key rather than by refusing to look.
Implementations§
Source§impl MemoryKeyRing
impl MemoryKeyRing
pub fn new() -> Self
Sourcepub fn rotate(&self)
pub fn rotate(&self)
Move to a new wrapping key.
The next mint draws a fresh KEK under the new generation; prior generations keep their keys, so envelopes sealed before the rotation still open. That is the property sealed-byte immutability rests on — rotation adds a version, it does not invalidate one — and it is what makes rotation something other than an outage.
Sourcepub fn retire_below(&self, generation: u64)
pub fn retire_below(&self, generation: u64)
Refuse to decrypt below generation, as a KMS version floor does.
Vault’s min_decryption_version and its equivalents elsewhere. Modelled
here because it is the one operator action that makes un-erased history
unreadable, and a ring that could not express it would leave
KeyError::Retired unreachable in every test — an error variant no
test can produce is a classification nothing proves the runtime honours.
Sourcepub fn current_key_id(&self) -> KeyId
pub fn current_key_id(&self) -> KeyId
The current wrapping key’s id.
Trait Implementations§
Source§impl Debug for MemoryKeyRing
impl Debug for MemoryKeyRing
Source§impl Default for MemoryKeyRing
impl Default for MemoryKeyRing
Source§impl KeyRing for MemoryKeyRing
impl KeyRing for MemoryKeyRing
Source§fn data_key<'life0, 'life1, 'async_trait>(
&'life0 self,
scope: &'life1 str,
) -> Pin<Box<dyn Future<Output = Result<(DataKey, WrappedKey), KeyError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
fn data_key<'life0, 'life1, 'async_trait>(
&'life0 self,
scope: &'life1 str,
) -> Pin<Box<dyn Future<Output = Result<(DataKey, WrappedKey), KeyError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
Source§fn open<'life0, 'life1, 'async_trait>(
&'life0 self,
wrapped: &'life1 WrappedKey,
) -> Pin<Box<dyn Future<Output = Result<DataKey, KeyError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
fn open<'life0, 'life1, 'async_trait>(
&'life0 self,
wrapped: &'life1 WrappedKey,
) -> Pin<Box<dyn Future<Output = Result<DataKey, KeyError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
Source§fn destroy<'life0, 'life1, 'life2, 'async_trait>(
&'life0 self,
scope: &'life1 str,
at: Timestamp,
reason: &'life2 str,
) -> Pin<Box<dyn Future<Output = Result<(), KeyError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
'life2: 'async_trait,
fn destroy<'life0, 'life1, 'life2, 'async_trait>(
&'life0 self,
scope: &'life1 str,
at: Timestamp,
reason: &'life2 str,
) -> Pin<Box<dyn Future<Output = Result<(), KeyError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
'life2: 'async_trait,
Auto Trait Implementations§
impl !Freeze for MemoryKeyRing
impl RefUnwindSafe for MemoryKeyRing
impl Send for MemoryKeyRing
impl Sync for MemoryKeyRing
impl Unpin for MemoryKeyRing
impl UnsafeUnpin for MemoryKeyRing
impl UnwindSafe for MemoryKeyRing
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more