Skip to main content

Module secrets

Module secrets 

Source
Expand description

Secrets: named values per org, behind pluggable drivers.

A secret is (org, name) with a value and a SecretMeta (driver, version, timestamps, labels). A Driver stores values; Secrets is the facade the daemon uses, and finds the driver holding each secret. The default driver is local: age ciphertext under the daemon’s state directory, encrypted to the daemon’s own key and any break-glass recipients (keys). Values are never listed: list and inspect return metadata only.

Compose files can also carry a value inline, age-encrypted (inline).

Re-exports§

pub use inline::decrypt_inline;
pub use inline::encrypt_inline;
pub use keys::KeyOrigin;
pub use keys::KeySources;
pub use keys::Keyring;
pub use keys::Recipient;
pub use keys::SecretsConfig;
pub use local::LocalDriver;

Modules§

inline
age encryption, and the inline form compose files carry (secrets: {x: {age: ...}}).
keys
The daemon’s age identity, the break-glass recipients, and where both come from.
local
The local driver: age ciphertext on the daemon’s disk.
onepassword
The onepassword driver: secrets that live in 1Password, read with the op CLI and a service-account token that belongs to the org.

Structs§

Opened
What Secrets::open found, for the daemon to log.
SecretMeta
What is known about a secret besides its value.
Secrets
The daemon’s secrets: every driver, local first and the default.

Constants§

MAX_VALUE_BYTES
The largest value a secret may hold.

Traits§

Driver
A secret store. Drivers that cannot write (an external vault read through a read-only token) keep the default create/set/delete, which refuse.

Functions§

validate_name
A valid secret name: 1-128 of [A-Za-z0-9_.-], not starting with . (so it can never be ., .. or a hidden file).