Skip to main content

Driver

Trait Driver 

Source
pub trait Driver: Send + Sync {
    // Required methods
    fn name(&self) -> &str;
    fn get(&self, org: &OrgId, name: &str) -> Result<(Vec<u8>, u64)>;
    fn version(&self, org: &OrgId, name: &str) -> Result<u64>;
    fn inspect(&self, org: &OrgId, name: &str) -> Result<SecretMeta>;
    fn list(&self, org: &OrgId) -> Result<Vec<SecretMeta>>;

    // Provided methods
    fn versions(&self, org: &OrgId, names: &[&str]) -> Vec<Result<u64>> ⓘ { ... }
    fn create(
        &self,
        org: &OrgId,
        name: &str,
        _value: &[u8],
        _labels: &BTreeMap<String, String>,
    ) -> Result<SecretMeta> { ... }
    fn set(&self, org: &OrgId, name: &str, _value: &[u8]) -> Result<u64> { ... }
    fn delete(&self, org: &OrgId, name: &str) -> Result<()> { ... }
    fn refresh(&self, org: &OrgId, name: &str) -> Result<SecretMeta> { ... }
    fn reencrypt(&self, _org: Option<&OrgId>) -> Result<usize> { ... }
}
Expand description

A secret store. Drivers that cannot write (an external vault read through a read-only token) keep the default create/set/delete, which refuse.

Required Methods§

Source

fn name(&self) -> &str

The name compose files and --driver use.

Source

fn get(&self, org: &OrgId, name: &str) -> Result<(Vec<u8>, u64)>

The value and its version.

Source

fn version(&self, org: &OrgId, name: &str) -> Result<u64>

The current version only: cheap, for polling.

Source

fn inspect(&self, org: &OrgId, name: &str) -> Result<SecretMeta>

Source

fn list(&self, org: &OrgId) -> Result<Vec<SecretMeta>>

Every secret in the org this driver holds: metadata, never values.

Provided Methods§

Source

fn versions(&self, org: &OrgId, names: &[&str]) -> Vec<Result<u64>> ⓘ

The current version of each name, in order: one polling round. Drivers whose secrets share a version (every field of a 1Password item) answer each group with one lookup.

Source

fn create( &self, org: &OrgId, name: &str, _value: &[u8], _labels: &BTreeMap<String, String>, ) -> Result<SecretMeta>

A new secret at version 1; fails if it exists.

Source

fn set(&self, org: &OrgId, name: &str, _value: &[u8]) -> Result<u64>

A new value; returns the new version. Creates the secret if missing.

Source

fn delete(&self, org: &OrgId, name: &str) -> Result<()>

Source

fn refresh(&self, org: &OrgId, name: &str) -> Result<SecretMeta>

Re-read the value from its source now (external drivers cache and poll). A no-op for drivers that are their own source.

Source

fn reencrypt(&self, _org: Option<&OrgId>) -> Result<usize>

Re-encrypt every value (in one org, or all) to the current recipients. Returns how many. A no-op for drivers that do not encrypt.

Dyn Compatibility§

This trait is dyn compatible.

In older versions of Rust, dyn compatibility was called "object safety".

Implementors§