pub struct PinnedKeyMap { /* private fields */ }Expand description
The DEFAULT AttestationKeyLookup as of the gate-3 redesign
(2026-09-13, BD-ratified per Jira CLEANLIB-379 comment 804236 —
see the module-level “Design history” doc above).
A compiled-in key_id -> PEM map. No network capability exists on this
type at all — there is no HTTP client field, no URL, nothing to fetch.
Self::lookup_pem is a pure in-memory match; an unrecognized key_id
returns Err(AttestationInvalid) immediately, which is what makes this
shape fail-closed rather than fail-open-via-fetch. This is deliberate:
the whole point of the redesign is that a verifier’s trust root cannot be
steered by an unsigned wire field talking to the same service being
verified.
Implementations§
Source§impl PinnedKeyMap
impl PinnedKeyMap
Sourcepub fn new() -> Self
pub fn new() -> Self
The built-in set: today’s staging + prod keys, exactly as
/v1/pubkeys reports them at the time of this SDK release.
Sourcepub fn with_extra_key(
self,
key_id: impl Into<String>,
pem: impl Into<String>,
) -> Self
pub fn with_extra_key( self, key_id: impl Into<String>, pem: impl Into<String>, ) -> Self
Pin an ADDITIONAL key the caller has verified out-of-band (e.g. a customer-specific signing key, or a new key_id whose fingerprint they checked against an independent publication per the redesign’s point 4). Does not touch the network — the caller supplies the PEM directly; this method only extends the in-memory map.
Trait Implementations§
Source§impl AttestationKeyLookup for PinnedKeyMap
impl AttestationKeyLookup for PinnedKeyMap
Source§fn lookup_pem<'life0, 'life1, 'async_trait>(
&'life0 self,
key_id: &'life1 str,
) -> Pin<Box<dyn Future<Output = Result<String, CleanLibraryError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
fn lookup_pem<'life0, 'life1, 'async_trait>(
&'life0 self,
key_id: &'life1 str,
) -> Pin<Box<dyn Future<Output = Result<String, CleanLibraryError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
key_id (the exact string carried on SignedAttestation.key_id
— the full KMS key-version resource path, e.g.
projects/.../cryptoKeys/cleanlib-cosign-staging/cryptoKeyVersions/1)
to a PEM-encoded SubjectPublicKeyInfo. Implementations should treat a
“no such key_id” answer as AttestationInvalid (permanent — retrying
the same key_id against the same catalog will not help) and a
network/5xx failure as Transport (transient — retry may succeed).Source§impl Clone for PinnedKeyMap
impl Clone for PinnedKeyMap
Source§fn clone(&self) -> PinnedKeyMap
fn clone(&self) -> PinnedKeyMap
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more