Skip to main content

derive_key

Function derive_key 

Source
pub fn derive_key(raw: &str) -> [u8; 32]
Expand description

Derive the 32-byte AES key from the raw configured value.

A value that is EXACTLY a 32-byte key (hex or canonical base64/base64url) is used directly; anything else is treated as a passphrase and hashed with a domain-separated SHA-256. Deterministic — the same input always maps to the same key, so restarts and rolling deploys decrypt existing rows.