pub fn derive_key(raw: &str) -> [u8; 32]Expand description
Derive the 32-byte AES key from the raw configured value.
A value that is EXACTLY a 32-byte key (hex or canonical base64/base64url) is used directly; anything else is treated as a passphrase and hashed with a domain-separated SHA-256. Deterministic — the same input always maps to the same key, so restarts and rolling deploys decrypt existing rows.