pub struct Secrets { /* private fields */ }Expand description
The daemon’s secrets: every driver, local first and the default.
Implementations§
Source§impl Secrets
impl Secrets
Sourcepub fn new(local: LocalDriver) -> Secrets
pub fn new(local: LocalDriver) -> Secrets
Just the local driver.
Sourcepub fn open(
state_dir: &Path,
keys: &KeySources,
config: &SecretsConfig,
) -> Result<Opened>
pub fn open( state_dir: &Path, keys: &KeySources, config: &SecretsConfig, ) -> Result<Opened>
Find (or generate) the daemon’s key, read the break-glass recipients,
and open the local store under state_dir.
Sourcepub fn open_existing(
state_dir: &Path,
keys: &KeySources,
config: &SecretsConfig,
) -> Result<Secrets>
pub fn open_existing( state_dir: &Path, keys: &KeySources, config: &SecretsConfig, ) -> Result<Secrets>
Open the store with an existing key only, for a client reading it
while no daemon runs (isb up). Never generates a key.
Sourcepub fn with_driver(self, d: Arc<dyn Driver>) -> Result<Secrets>
pub fn with_driver(self, d: Arc<dyn Driver>) -> Result<Secrets>
Add a driver. Names are unique.
pub fn driver_names(&self) -> Vec<String>
pub fn keyring(&self) -> &Arc<Keyring> ⓘ
Sourcepub fn recipients(&self) -> Vec<String>
pub fn recipients(&self) -> Vec<String>
The recipient set, as strings (age1…, ssh-…).
Sourcepub fn create(
&self,
org: &OrgId,
name: &str,
driver: Option<&str>,
value: &[u8],
labels: &BTreeMap<String, String>,
) -> Result<SecretMeta>
pub fn create( &self, org: &OrgId, name: &str, driver: Option<&str>, value: &[u8], labels: &BTreeMap<String, String>, ) -> Result<SecretMeta>
A new secret in driver (default local); fails if any driver has
one by that name.
Sourcepub fn set(&self, org: &OrgId, name: &str, value: &[u8]) -> Result<SecretMeta>
pub fn set(&self, org: &OrgId, name: &str, value: &[u8]) -> Result<SecretMeta>
A new value for a secret, in the driver holding it; a missing one is
created in local.
pub fn get(&self, org: &OrgId, name: &str) -> Result<(Vec<u8>, SecretMeta)>
pub fn version(&self, org: &OrgId, name: &str) -> Result<u64>
Sourcepub fn put(&self, org: &OrgId, name: &str, value: &[u8]) -> Result<SecretMeta>
pub fn put(&self, org: &OrgId, name: &str, value: &[u8]) -> Result<SecretMeta>
Store value under name unless it already holds exactly that, so
the version moves only when the value does.
Sourcepub fn get_in(
&self,
driver: &str,
org: &OrgId,
name: &str,
) -> Result<(Vec<u8>, u64)>
pub fn get_in( &self, driver: &str, org: &OrgId, name: &str, ) -> Result<(Vec<u8>, u64)>
A value read through a named driver, by that driver’s reference
(which need not be a store name: an op:// path, say).
Sourcepub fn version_in(&self, driver: &str, org: &OrgId, name: &str) -> Result<u64>
pub fn version_in(&self, driver: &str, org: &OrgId, name: &str) -> Result<u64>
The current version in a named driver: cheap, for polling.
Sourcepub fn refresh_in(&self, driver: &str, org: &OrgId, name: &str) -> Result<u64>
pub fn refresh_in(&self, driver: &str, org: &OrgId, name: &str) -> Result<u64>
Re-read from the source through a named driver.
pub fn inspect(&self, org: &OrgId, name: &str) -> Result<SecretMeta>
Sourcepub fn list(&self, org: &OrgId) -> Result<Vec<SecretMeta>>
pub fn list(&self, org: &OrgId) -> Result<Vec<SecretMeta>>
Every driver’s secrets in the org, by name.
pub fn delete(&self, org: &OrgId, name: &str) -> Result<()>
pub fn refresh(&self, org: &OrgId, name: &str) -> Result<SecretMeta>
Sourcepub fn reencrypt(&self, org: Option<&OrgId>) -> Result<usize>
pub fn reencrypt(&self, org: Option<&OrgId>) -> Result<usize>
Re-encrypt every value to the current recipients, in one org or all.
Sourcepub fn decrypt_inline(&self, text: &str) -> Result<Vec<u8>>
pub fn decrypt_inline(&self, text: &str) -> Result<Vec<u8>>
Decrypt a compose file’s inline age: value with the daemon’s key.
Sourcepub fn encrypt_inline(&self, value: &[u8]) -> Result<String>
pub fn encrypt_inline(&self, value: &[u8]) -> Result<String>
Inline ciphertext to the daemon’s recipients.