Skip to main content

EncryptedBlobStore

Struct EncryptedBlobStore 

Source
pub struct EncryptedBlobStore<S> { /* private fields */ }
Expand description

Blob-store decorator that exposes plaintext while storing deterministic authenticated ciphertext.

Blob identifiers are digests of the encrypted object. Listing, deletion, timestamps, and cleartext root records pass through to the wrapped store. The key set is an immutable snapshot; a manifest reload or rotation replaces the decorator rather than resolving a KMS key on each blob read.

Implementations§

Source§

impl<S> EncryptedBlobStore<S>

Source

pub fn new( inner: S, current_epoch: u32, keys: impl IntoIterator<Item = (u32, SecretKey)>, ) -> Result<Self, StoreError>

Creates a decorator with all readable epochs and the epoch used by new writes.

§Errors

Returns StoreError::MissingEncryptionKey when current_epoch is not present in keys.

Source

pub fn with_key(inner: S, epoch: u32, key: SecretKey) -> Self

Creates a single-epoch decorator.

Source

pub fn inner(&self) -> &S

Returns the wrapped ciphertext store.

Source

pub fn into_inner(self) -> S

Consumes the decorator and returns the wrapped store.

Source

pub fn current_epoch(&self) -> u32

Returns the epoch used for new writes.

Trait Implementations§

Source§

impl<S: BlobStore> BlobStore for EncryptedBlobStore<S>

Source§

fn put<'life0, 'life1, 'async_trait>( &'life0 self, bytes: &'life1 [u8], ) -> Pin<Box<dyn Future<Output = Result<BlobId, StoreError>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Stores bytes and returns their content id. Read more
Source§

fn get<'life0, 'life1, 'async_trait>( &'life0 self, id: &'life1 BlobId, ) -> Pin<Box<dyn Future<Output = Result<Option<Vec<u8>>, StoreError>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Loads bytes by id, returning None when missing. Read more
Source§

fn contains<'life0, 'life1, 'async_trait>( &'life0 self, id: &'life1 BlobId, ) -> Pin<Box<dyn Future<Output = Result<bool, StoreError>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Reports whether a blob is present. Read more
Source§

fn put_if_absent<'life0, 'life1, 'async_trait>( &'life0 self, bytes: &'life1 [u8], ) -> Pin<Box<dyn Future<Output = Result<BlobId, StoreError>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Stores bytes only when their content id is absent, skipping the upload for blobs the store already holds. Read more
Source§

fn delete<'life0, 'life1, 'async_trait>( &'life0 self, id: &'life1 BlobId, ) -> Pin<Box<dyn Future<Output = Result<(), StoreError>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Deletes a blob during garbage collection. Missing blobs are ignored. Read more
Source§

fn list<'life0, 'async_trait>( &'life0 self, ) -> Pin<Box<dyn Future<Output = Result<BlobIdStream, StoreError>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait,

Lists all blob identifiers known to this backend. Read more
Source§

fn modified_at<'life0, 'life1, 'async_trait>( &'life0 self, id: &'life1 BlobId, ) -> Pin<Box<dyn Future<Output = Result<Option<SystemTime>, StoreError>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Returns the blob’s creation/last-modification time when available. Backends without timestamps return None, which conservatively keeps the blob whenever a non-zero retention window is active. Read more
Source§

impl<S: Clone> Clone for EncryptedBlobStore<S>

Source§

fn clone(&self) -> EncryptedBlobStore<S>

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl<S: RootStore> RootStore for EncryptedBlobStore<S>

Source§

fn get_root<'life0, 'life1, 'async_trait>( &'life0 self, name: &'life1 str, ) -> Pin<Box<dyn Future<Output = Result<Option<Vec<u8>>, StoreError>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Reads a root pointer. Read more
Source§

fn cas_root<'life0, 'life1, 'life2, 'life3, 'async_trait>( &'life0 self, name: &'life1 str, expected: Option<&'life2 [u8]>, new: &'life3 [u8], ) -> Pin<Box<dyn Future<Output = Result<(), StoreError>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait, 'life2: 'async_trait, 'life3: 'async_trait,

Publishes a root only if the stored pointer equals expected. Read more
Source§

fn delete_root<'life0, 'life1, 'async_trait>( &'life0 self, name: &'life1 str, ) -> Pin<Box<dyn Future<Output = Result<(), StoreError>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Removes a root pointer. Missing roots are ignored. Read more
Source§

fn list_roots<'life0, 'life1, 'async_trait>( &'life0 self, prefix: &'life1 str, ) -> Pin<Box<dyn Future<Output = Result<Vec<String>, StoreError>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Lists root names beginning with prefix, in sorted order. Read more

Auto Trait Implementations§

§

impl<S> Freeze for EncryptedBlobStore<S>
where S: Freeze,

§

impl<S> RefUnwindSafe for EncryptedBlobStore<S>
where S: RefUnwindSafe,

§

impl<S> Send for EncryptedBlobStore<S>
where S: Send,

§

impl<S> Sync for EncryptedBlobStore<S>
where S: Sync,

§

impl<S> Unpin for EncryptedBlobStore<S>
where S: Unpin,

§

impl<S> UnsafeUnpin for EncryptedBlobStore<S>
where S: UnsafeUnpin,

§

impl<S> UnwindSafe for EncryptedBlobStore<S>
where S: UnwindSafe,

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoRequest<T> for T

Source§

fn into_request(self) -> Request<T>

Wrap the input message T in a tonic::Request
Source§

impl<L> LayerExt<L> for L

Source§

fn named_layer<S>(&self, service: S) -> Layered<<L as Layer<S>>::Service, S>
where L: Layer<S>,

Applies the layer to a service and wraps it in Layered.
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> SegmentReader for T
where T: BlobStore + ?Sized,

Source§

fn read_segment<'life0, 'life1, 'async_trait>( &'life0 self, id: &'life1 BlobId, ) -> Pin<Box<dyn Future<Output = Result<Option<Vec<u8>>, StoreError>> + Send + 'async_trait>>
where 'life0: 'async_trait, 'life1: 'async_trait, T: 'async_trait,

Reads an immutable segment from authoritative storage.
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more