pub enum EnvelopeSpec {
None,
Local {
kek_file: PathBuf,
},
Vault {
addr: String,
key: String,
token: String,
},
}Expand description
A resolved secrets-at-rest envelope choice (the caller maps its config to this, resolving any Vault token from the environment — never from a file).
Variants§
None
No wrapping — secrets stored cleartext (single-node dev / opt-out).
Local
Machine-local AES-256-GCM KEK at kek_file.
Vault
Vault Transit key at addr, authenticated by token.
Auto Trait Implementations§
impl Freeze for EnvelopeSpec
impl RefUnwindSafe for EnvelopeSpec
impl Send for EnvelopeSpec
impl Sync for EnvelopeSpec
impl Unpin for EnvelopeSpec
impl UnsafeUnpin for EnvelopeSpec
impl UnwindSafe for EnvelopeSpec
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more