pub struct VaultEnvelope { /* private fields */ }Expand description
A KeyEnvelope backed by Vault’s Transit engine: wrap/
unwrap are transit/encrypt|decrypt/<key> round-trips, so the KEK never
leaves Vault and every cluster node unwraps through the same service (no
shared local key file). Any KMS exposing a Vault-compatible Transit API works.
The token is passed in from the environment (never stored in config files).
Implementations§
Trait Implementations§
Source§impl KeyEnvelope for VaultEnvelope
impl KeyEnvelope for VaultEnvelope
Source§fn wrap<'life0, 'life1, 'async_trait>(
&'life0 self,
plaintext: &'life1 [u8],
) -> Pin<Box<dyn Future<Output = Result<Vec<u8>, EnvelopeError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
fn wrap<'life0, 'life1, 'async_trait>(
&'life0 self,
plaintext: &'life1 [u8],
) -> Pin<Box<dyn Future<Output = Result<Vec<u8>, EnvelopeError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
Wrap
plaintext, returning an opaque blob to store at rest.Auto Trait Implementations§
impl !RefUnwindSafe for VaultEnvelope
impl !UnwindSafe for VaultEnvelope
impl Freeze for VaultEnvelope
impl Send for VaultEnvelope
impl Sync for VaultEnvelope
impl Unpin for VaultEnvelope
impl UnsafeUnpin for VaultEnvelope
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more