pub enum SignerConfig {
Local {
private_key: String,
},
Vault {
address: String,
key: String,
token_env: String,
alg: TokenAlg,
},
AwsKms {
key_id: String,
region: Option<String>,
},
GcpKms {
key_version: String,
access_token_env: String,
},
AzureKv {
vault_url: String,
key: String,
key_version: String,
access_token_env: String,
},
Pkcs11 {
module: String,
token_label: String,
key_label: String,
pin_env: String,
alg: TokenAlg,
},
}Expand description
Which signer backend issues control-plane tokens, and its parameters. Selected
by the operator (config [auth.signer]); the default is SignerConfig::Local.
Variants§
Local
An in-process key ("<alg>:<hex>") — the default / dev backend.
Vault
A HashiCorp Vault Transit key. Token from token_env.
Fields
AwsKms
An AWS KMS asymmetric signing key (ES256 only). Credentials from the standard AWS provider chain (env / profile / IMDS).
Fields
GcpKms
A GCP Cloud KMS asymmetric signing key version (ES256 only). Access token
from access_token_env (a sidecar / workload-identity refreshes it).
Fields
AzureKv
An Azure Key Vault signing key (ES256 only). Access token from
access_token_env (managed identity / a sidecar refreshes it).
Fields
Pkcs11
A PKCS#11 HSM key. PIN from pin_env.
Trait Implementations§
Source§impl Clone for SignerConfig
impl Clone for SignerConfig
Source§fn clone(&self) -> SignerConfig
fn clone(&self) -> SignerConfig
Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
Performs copy-assignment from
source. Read moreAuto Trait Implementations§
impl Freeze for SignerConfig
impl RefUnwindSafe for SignerConfig
impl Send for SignerConfig
impl Sync for SignerConfig
impl Unpin for SignerConfig
impl UnsafeUnpin for SignerConfig
impl UnwindSafe for SignerConfig
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more