pub struct SecretsConfig {
pub envelope: String,
pub kek_file: Option<PathBuf>,
pub vault: Option<VaultSecretsConfig>,
}Expand description
secrets section — envelope encryption for private keys at rest.
Fields§
§envelope: StringBackend: "local" (machine-local AES-256-GCM KEK) or "vault" (Vault
Transit). Empty/other ⇒ no wrapping. In a cluster a local KEK must be the
same file on every node (wrapped certs replicate); Vault avoids that.
kek_file: Option<PathBuf>Local-KEK key file (envelope = "local"). Default
<data-dir>/secrets/kek. Auto-generated 0600 if absent.
vault: Option<VaultSecretsConfig>Vault Transit config (envelope = "vault").
Trait Implementations§
Source§impl Clone for SecretsConfig
impl Clone for SecretsConfig
Source§fn clone(&self) -> SecretsConfig
fn clone(&self) -> SecretsConfig
Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
Performs copy-assignment from
source. Read moreSource§impl Debug for SecretsConfig
impl Debug for SecretsConfig
Source§impl Default for SecretsConfig
impl Default for SecretsConfig
Source§fn default() -> SecretsConfig
fn default() -> SecretsConfig
Returns the “default value” for a type. Read more
Source§impl<'de> Deserialize<'de> for SecretsConfigwhere
SecretsConfig: Default,
impl<'de> Deserialize<'de> for SecretsConfigwhere
SecretsConfig: Default,
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Deserialize this value from the given Serde deserializer. Read more
Auto Trait Implementations§
impl Freeze for SecretsConfig
impl RefUnwindSafe for SecretsConfig
impl Send for SecretsConfig
impl Sync for SecretsConfig
impl Unpin for SecretsConfig
impl UnsafeUnpin for SecretsConfig
impl UnwindSafe for SecretsConfig
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more