pub struct DevBackend { /* private fields */ }Expand description
Development backend that stores ciphertexts in-memory with optional .env persistence.
Implementations§
Source§impl DevBackend
impl DevBackend
Sourcepub fn with_persistence<P: Into<PathBuf>>(path: P) -> Result<Self>
pub fn with_persistence<P: Into<PathBuf>>(path: P) -> Result<Self>
Construct a backend that persists state to the specified .env file.
Sourcepub fn from_env() -> Result<Self>
pub fn from_env() -> Result<Self>
Construct from environment configuration. If the configured file does not exist, the backend falls back to in-memory storage.
Sourcepub fn export_excluding(
src: &Path,
dest: &Path,
exclude: &[&SecretUri],
) -> Result<()>
pub fn export_excluding( src: &Path, dest: &Path, exclude: &[&SecretUri], ) -> Result<()>
Write a sanitized copy of the dev-store persisted at src to dest,
hard-excluding every entry whose URI is in exclude.
Excluded URIs leave no residual ciphertext in dest: the whole key is
dropped from the snapshot before it is ever written, unlike the
tombstoning SecretsBackend::delete (which leaves the prior live
version’s encrypted record on disk). Intended for stripping
control-plane material — e.g. a bound deployer credential — before a store
is staged into an untrusted runtime seed.
The operation is transactional and lock-safe:
- it reads a consistent snapshot of
srcread-only under a shared lock (which conflicts with the writer’s exclusive lock), so a concurrent writer cannot yield a torn or empty result and asrcremoved between calls fails loudly instead of being recreated empty; - it never opens
srcfor writing; - it builds the sanitized store in a private temp file in
dest’s directory and publishes it with a no-clobber rename, sodestnever transiently holds an excluded entry and any failure leavesdestuntouched.
§Limitation
The alias and no-clobber guards resolve pathnames, so the source-integrity
and no-clobber guarantees assume the directories on the src and dest
paths are not concurrently manipulated by another actor (e.g. a symlink
in dest’s parent repointed between the snapshot and the publish). Callers
must stage to a directory they control — a private temp dir is ideal.
Hardening against a hostile dest-parent (openat/O_NOFOLLOW
directory-handle operations) is out of scope for this local-store staging
primitive.
src must exist and dest must be a fresh path that does not yet
exist and does not resolve to src — a pre-existing dest (including
src, a symlink to it, or a file a live backend still holds open) is
rejected rather than replaced, since replacing it could let a stale
in-memory snapshot resurrect an excluded record at dest.
Trait Implementations§
Source§impl Clone for DevBackend
impl Clone for DevBackend
Source§fn clone(&self) -> DevBackend
fn clone(&self) -> DevBackend
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Default for DevBackend
impl Default for DevBackend
Source§impl SecretsBackend for DevBackend
impl SecretsBackend for DevBackend
fn put(&self, record: SecretRecord) -> Result<SecretVersion>
fn get( &self, uri: &SecretUri, version: Option<u64>, ) -> Result<Option<VersionedSecret>>
fn list( &self, scope: &Scope, category_prefix: Option<&str>, name_prefix: Option<&str>, ) -> Result<Vec<SecretListItem>>
fn delete(&self, uri: &SecretUri) -> Result<SecretVersion>
fn versions(&self, uri: &SecretUri) -> Result<Vec<SecretVersion>>
fn exists(&self, uri: &SecretUri) -> Result<bool>
Auto Trait Implementations§
impl !RefUnwindSafe for DevBackend
impl !UnwindSafe for DevBackend
impl Freeze for DevBackend
impl Send for DevBackend
impl Sync for DevBackend
impl Unpin for DevBackend
impl UnsafeUnpin for DevBackend
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> FutureExt for T
impl<T> FutureExt for T
Source§fn with_context(self, otel_cx: Context) -> WithContext<Self>
fn with_context(self, otel_cx: Context) -> WithContext<Self>
Source§fn with_current_context(self) -> WithContext<Self>
fn with_current_context(self) -> WithContext<Self>
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
Source§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
T in a tonic::Request