pub struct EncryptedBlobStore<S> { /* private fields */ }Expand description
Blob-store decorator that exposes plaintext while storing deterministic authenticated ciphertext.
Blob identifiers are digests of the encrypted object. Listing, deletion, timestamps, and cleartext root records pass through to the wrapped store. The key set is an immutable snapshot; a manifest reload or rotation replaces the decorator rather than resolving a KMS key on each blob read.
Implementations§
Source§impl<S> EncryptedBlobStore<S>
impl<S> EncryptedBlobStore<S>
Sourcepub fn new(
inner: S,
current_epoch: u32,
keys: impl IntoIterator<Item = (u32, SecretKey)>,
) -> Result<Self, StoreError>
pub fn new( inner: S, current_epoch: u32, keys: impl IntoIterator<Item = (u32, SecretKey)>, ) -> Result<Self, StoreError>
Creates a decorator with all readable epochs and the epoch used by new writes.
§Errors
Returns StoreError::MissingEncryptionKey when current_epoch is not
present in keys.
Sourcepub fn with_key(inner: S, epoch: u32, key: SecretKey) -> Self
pub fn with_key(inner: S, epoch: u32, key: SecretKey) -> Self
Creates a single-epoch decorator.
Sourcepub fn into_inner(self) -> S
pub fn into_inner(self) -> S
Consumes the decorator and returns the wrapped store.
Sourcepub fn current_epoch(&self) -> u32
pub fn current_epoch(&self) -> u32
Returns the epoch used for new writes.
Trait Implementations§
Source§impl<S: BlobStore> BlobStore for EncryptedBlobStore<S>
impl<S: BlobStore> BlobStore for EncryptedBlobStore<S>
Source§fn put<'life0, 'life1, 'async_trait>(
&'life0 self,
bytes: &'life1 [u8],
) -> Pin<Box<dyn Future<Output = Result<BlobId, StoreError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
fn put<'life0, 'life1, 'async_trait>(
&'life0 self,
bytes: &'life1 [u8],
) -> Pin<Box<dyn Future<Output = Result<BlobId, StoreError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
Stores bytes and returns their content id. Read more
Source§fn get<'life0, 'life1, 'async_trait>(
&'life0 self,
id: &'life1 BlobId,
) -> Pin<Box<dyn Future<Output = Result<Option<Vec<u8>>, StoreError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
fn get<'life0, 'life1, 'async_trait>(
&'life0 self,
id: &'life1 BlobId,
) -> Pin<Box<dyn Future<Output = Result<Option<Vec<u8>>, StoreError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
Loads bytes by id, returning
None when missing. Read moreSource§fn contains<'life0, 'life1, 'async_trait>(
&'life0 self,
id: &'life1 BlobId,
) -> Pin<Box<dyn Future<Output = Result<bool, StoreError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
fn contains<'life0, 'life1, 'async_trait>(
&'life0 self,
id: &'life1 BlobId,
) -> Pin<Box<dyn Future<Output = Result<bool, StoreError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
Reports whether a blob is present. Read more
Source§fn put_if_absent<'life0, 'life1, 'async_trait>(
&'life0 self,
bytes: &'life1 [u8],
) -> Pin<Box<dyn Future<Output = Result<BlobId, StoreError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
fn put_if_absent<'life0, 'life1, 'async_trait>(
&'life0 self,
bytes: &'life1 [u8],
) -> Pin<Box<dyn Future<Output = Result<BlobId, StoreError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
Stores bytes only when their content id is absent, skipping the
upload for blobs the store already holds. Read more
Source§fn delete<'life0, 'life1, 'async_trait>(
&'life0 self,
id: &'life1 BlobId,
) -> Pin<Box<dyn Future<Output = Result<(), StoreError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
fn delete<'life0, 'life1, 'async_trait>(
&'life0 self,
id: &'life1 BlobId,
) -> Pin<Box<dyn Future<Output = Result<(), StoreError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
Deletes a blob during garbage collection. Missing blobs are ignored. Read more
Source§fn list<'life0, 'async_trait>(
&'life0 self,
) -> Pin<Box<dyn Future<Output = Result<BlobIdStream, StoreError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
fn list<'life0, 'async_trait>(
&'life0 self,
) -> Pin<Box<dyn Future<Output = Result<BlobIdStream, StoreError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
Lists all blob identifiers known to this backend. Read more
Source§fn modified_at<'life0, 'life1, 'async_trait>(
&'life0 self,
id: &'life1 BlobId,
) -> Pin<Box<dyn Future<Output = Result<Option<SystemTime>, StoreError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
fn modified_at<'life0, 'life1, 'async_trait>(
&'life0 self,
id: &'life1 BlobId,
) -> Pin<Box<dyn Future<Output = Result<Option<SystemTime>, StoreError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
Returns the blob’s creation/last-modification time when available.
Backends without timestamps return
None, which conservatively keeps
the blob whenever a non-zero retention window is active. Read moreSource§impl<S: Clone> Clone for EncryptedBlobStore<S>
impl<S: Clone> Clone for EncryptedBlobStore<S>
Source§fn clone(&self) -> EncryptedBlobStore<S>
fn clone(&self) -> EncryptedBlobStore<S>
Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
Performs copy-assignment from
source. Read moreSource§impl<S: RootStore> RootStore for EncryptedBlobStore<S>
impl<S: RootStore> RootStore for EncryptedBlobStore<S>
Source§fn get_root<'life0, 'life1, 'async_trait>(
&'life0 self,
name: &'life1 str,
) -> Pin<Box<dyn Future<Output = Result<Option<Vec<u8>>, StoreError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
fn get_root<'life0, 'life1, 'async_trait>(
&'life0 self,
name: &'life1 str,
) -> Pin<Box<dyn Future<Output = Result<Option<Vec<u8>>, StoreError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
Reads a root pointer. Read more
Source§fn cas_root<'life0, 'life1, 'life2, 'life3, 'async_trait>(
&'life0 self,
name: &'life1 str,
expected: Option<&'life2 [u8]>,
new: &'life3 [u8],
) -> Pin<Box<dyn Future<Output = Result<(), StoreError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
'life2: 'async_trait,
'life3: 'async_trait,
fn cas_root<'life0, 'life1, 'life2, 'life3, 'async_trait>(
&'life0 self,
name: &'life1 str,
expected: Option<&'life2 [u8]>,
new: &'life3 [u8],
) -> Pin<Box<dyn Future<Output = Result<(), StoreError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
'life2: 'async_trait,
'life3: 'async_trait,
Publishes a root only if the stored pointer equals
expected. Read moreSource§fn delete_root<'life0, 'life1, 'async_trait>(
&'life0 self,
name: &'life1 str,
) -> Pin<Box<dyn Future<Output = Result<(), StoreError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
fn delete_root<'life0, 'life1, 'async_trait>(
&'life0 self,
name: &'life1 str,
) -> Pin<Box<dyn Future<Output = Result<(), StoreError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
Removes a root pointer. Missing roots are ignored. Read more
Source§fn list_roots<'life0, 'life1, 'async_trait>(
&'life0 self,
prefix: &'life1 str,
) -> Pin<Box<dyn Future<Output = Result<Vec<String>, StoreError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
fn list_roots<'life0, 'life1, 'async_trait>(
&'life0 self,
prefix: &'life1 str,
) -> Pin<Box<dyn Future<Output = Result<Vec<String>, StoreError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
Lists root names beginning with
prefix, in sorted order. Read moreAuto Trait Implementations§
impl<S> Freeze for EncryptedBlobStore<S>where
S: Freeze,
impl<S> RefUnwindSafe for EncryptedBlobStore<S>where
S: RefUnwindSafe,
impl<S> Send for EncryptedBlobStore<S>where
S: Send,
impl<S> Sync for EncryptedBlobStore<S>where
S: Sync,
impl<S> Unpin for EncryptedBlobStore<S>where
S: Unpin,
impl<S> UnsafeUnpin for EncryptedBlobStore<S>where
S: UnsafeUnpin,
impl<S> UnwindSafe for EncryptedBlobStore<S>where
S: UnwindSafe,
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
Source§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
Wrap the input message
T in a tonic::RequestSource§impl<T> SegmentReader for T
impl<T> SegmentReader for T
Source§fn read_segment<'life0, 'life1, 'async_trait>(
&'life0 self,
id: &'life1 BlobId,
) -> Pin<Box<dyn Future<Output = Result<Option<Vec<u8>>, StoreError>> + Send + 'async_trait>>where
'life0: 'async_trait,
'life1: 'async_trait,
T: 'async_trait,
fn read_segment<'life0, 'life1, 'async_trait>(
&'life0 self,
id: &'life1 BlobId,
) -> Pin<Box<dyn Future<Output = Result<Option<Vec<u8>>, StoreError>> + Send + 'async_trait>>where
'life0: 'async_trait,
'life1: 'async_trait,
T: 'async_trait,
Reads an immutable segment from authoritative storage.