Skip to main content

TransitEngine

Struct TransitEngine 

Source
pub struct TransitEngine { /* private fields */ }
Expand description

The Transit Engine provides encryption-as-a-service.

Applications can encrypt and decrypt data without ever seeing the keys.

Implementations§

Source§

impl TransitEngine

Source

pub async fn new( data_path: impl AsRef<Path>, master_key: MasterKey, ) -> Result<Self, TransitError>

Creates a new TransitEngine with the given storage path and master key.

Source

pub async fn create_key( &self, name: &str, config: KeyConfig, ) -> Result<TransitKey, TransitError>

Creates a new transit key.

Source

pub async fn get_key(&self, name: &str) -> Result<TransitKey, TransitError>

Gets metadata for a transit key.

Source

pub async fn list_keys(&self) -> Result<Vec<String>, TransitError>

Lists all transit key names.

Source

pub async fn list_versions( &self, name: &str, ) -> Result<Vec<KeyVersionInfo>, TransitError>

Lists all versions of a key.

Source

pub async fn rotate_key(&self, name: &str) -> Result<u32, TransitError>

Rotates a key to a new version.

Source

pub async fn delete_key(&self, name: &str) -> Result<(), TransitError>

Deletes a transit key (if deletion is allowed).

Source

pub async fn update_key_config( &self, name: &str, min_encryption_version: Option<u32>, min_decryption_version: Option<u32>, deletion_allowed: Option<bool>, ) -> Result<(), TransitError>

Updates key configuration (min versions, etc.).

Source

pub async fn encrypt( &self, name: &str, plaintext: &[u8], ) -> Result<String, TransitError>

Encrypts plaintext using the latest version of a key.

Returns ciphertext in format: egide:v{version}:{base64}

Source

pub async fn encrypt_with_version( &self, name: &str, plaintext: &[u8], version: u32, ) -> Result<String, TransitError>

Encrypts plaintext using a specific key version.

Source

pub async fn decrypt( &self, name: &str, ciphertext: &str, ) -> Result<Vec<u8>, TransitError>

Decrypts ciphertext.

Automatically determines the key version from the ciphertext format.

Source

pub async fn rewrap( &self, name: &str, ciphertext: &str, ) -> Result<String, TransitError>

Rewraps ciphertext with the latest key version.

This decrypts and re-encrypts without exposing plaintext to the caller.

Source

pub async fn generate_datakey( &self, name: &str, ) -> Result<DataKey, TransitError>

Generates a new data encryption key (DEK).

Returns both the plaintext key (for immediate use) and the wrapped key (for storage). The plaintext key should be used and then discarded.

Source

pub async fn decrypt_datakey( &self, name: &str, wrapped: &str, ) -> Result<Vec<u8>, TransitError>

Decrypts a wrapped data key.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more