Expand description
Secrets: named values per org, behind pluggable drivers.
A secret is (org, name) with a value and a SecretMeta (driver,
version, timestamps, labels). A Driver stores values; Secrets is
the facade the daemon uses, and finds the driver holding each secret. The
default driver is local: age ciphertext under the daemon’s state
directory, encrypted to the daemon’s own key and any break-glass
recipients (keys). Values are never listed: list and inspect
return metadata only.
Compose files can also carry a value inline, age-encrypted (inline).
Re-exports§
pub use inline::decrypt_inline;pub use inline::encrypt_inline;pub use keys::KeyOrigin;pub use keys::KeySources;pub use keys::Keyring;pub use keys::Recipient;pub use keys::SecretsConfig;pub use local::LocalDriver;
Modules§
- inline
- age encryption, and the inline form compose files carry
(
secrets: {x: {age: ...}}). - keys
- The daemon’s age identity, the break-glass recipients, and where both come from.
- local
- The
localdriver: age ciphertext on the daemon’s disk. - onepassword
- The
onepassworddriver: secrets that live in 1Password, read with theopCLI and a service-account token that belongs to the org.
Structs§
- Opened
- What
Secrets::openfound, for the daemon to log. - Secret
Meta - What is known about a secret besides its value.
- Secrets
- The daemon’s secrets: every driver,
localfirst and the default.
Constants§
- MAX_
VALUE_ BYTES - The largest value a secret may hold.
Traits§
- Driver
- A secret store. Drivers that cannot write (an external vault read through
a read-only token) keep the default
create/set/delete, which refuse.
Functions§
- validate_
name - A valid secret name: 1-128 of
[A-Za-z0-9_.-], not starting with.(so it can never be.,..or a hidden file).