pub struct S3CredentialConfig {
pub access_key_id: String,
pub secret_access_key: String,
}Expand description
[serve.s3_credential] — a node-level base S3 credential source (#505) sourcing the base AWS
credential from boatramp’s [secrets] sealed store rather than the ambient env chain. Consumed by
BOTH the S3 blob object backend and the AWS blob-upload cloud minter (one shared source, since it is
the same bucket key). Additive/non-breaking: absent ⇒ the ambient AWS env chain (unchanged).
The access_key_id is a public identifier (plain config). The secret_access_key is a secret
reference in the same scheme the guest secrets map uses: boatramp:<name> (the project-scoped
sealed store, resolved under the reserved default project — multi-tenant-safe, never the host env),
env:<VAR> / a bare <VAR> (the operator’s own environment — honored only when the posture’s
allow_env_secret_refs is set), unsealed at serve startup via the [secrets] [KeyEnvelope]. The
resolved plaintext is held in memory only (never env/argv/git/logs); see the redacted
SealedS3Credential the resolver produces.
Fields§
§access_key_id: StringThe AWS access key id — a public identifier, not a secret, so it is plain config (mirrors
how an access_key_id is a public value in the S3-ingress credential model). Empty is refused
at resolution.
secret_access_key: StringThe secret access key, expressed as a secret reference (never the raw secret in the
config text): boatramp:<name> (the project-scoped sealed store), env:<VAR> or a bare <VAR>
(the operator env, posture-gated by allow_env_secret_refs). Unsealed at startup via the
[secrets] envelope; the resolved value is redacted from Debug/logs. A boatramp:/env:
ref configured with NO [secrets] envelope is a fail-closed startup error.
Trait Implementations§
Source§impl Clone for S3CredentialConfig
impl Clone for S3CredentialConfig
Source§impl Debug for S3CredentialConfig
impl Debug for S3CredentialConfig
Source§impl Default for S3CredentialConfig
impl Default for S3CredentialConfig
Source§impl<'de> Deserialize<'de> for S3CredentialConfig
impl<'de> Deserialize<'de> for S3CredentialConfig
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Auto Trait Implementations§
impl Freeze for S3CredentialConfig
impl RefUnwindSafe for S3CredentialConfig
impl Send for S3CredentialConfig
impl Sync for S3CredentialConfig
impl Unpin for S3CredentialConfig
impl UnsafeUnpin for S3CredentialConfig
impl UnwindSafe for S3CredentialConfig
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more