pub struct SecretDef {
pub file: Option<String>,
pub environment: Option<String>,
pub external: bool,
pub name: Option<String>,
pub age: Option<String>,
pub driver: Option<String>,
pub refresh: Option<String>,
pub on_change: Option<OnChange>,
pub rotate: Option<Vec<String>>,
}Expand description
Where a secret’s value comes from. Exactly one source.
Fields§
§file: Option<String>A host file holding the value (relative to the compose file).
environment: Option<String>An environment variable of whoever deploys the file (isb up, or the
client calling isb stack deploy).
external: boolThe secret already exists in the org’s secret store (isb secret create), under name (default: the key).
name: Option<String>With external: the store’s name for it. With driver: the
driver’s reference (a 1Password op:// path, say).
age: Option<String>The value, age-encrypted to the daemon’s recipients (isb secret encrypt): ASCII-armored, or base64 of the binary format.
driver: Option<String>Read through this secrets driver, from name.
refresh: Option<String>With driver: how often isb serve checks the driver for a new
version (30m, 1h; default 1h). A new version rolls the services
using it.
on_change: Option<OnChange>What a new version does to the services using it under isb serve:
roll (default), restart or none. A service’s own reference
(secrets: [{source, on_change}], {secret, on_change}) overrides it.
rotate: Option<Vec<String>>Under isb serve: argv run in one running replica of each service
using the secret when it gets a new version, before any replica is
given it, to make the new value take effect where the old one is
stored (a database user’s password). It reads the new value on stdin
and runs with the replica’s own environment, which still holds the
old one. A failure stops the change: isb secret set stores nothing,
and a driver’s new version is not taken up.
Implementations§
Source§impl SecretDef
impl SecretDef
Sourcepub fn validate(&self) -> Result<(), String>
pub fn validate(&self) -> Result<(), String>
Check that exactly one source is given: file, environment,
external, age, or driver with name.
Sourcepub fn store_name<'a>(&'a self, key: &'a str) -> Option<&'a str>
pub fn store_name<'a>(&'a self, key: &'a str) -> Option<&'a str>
The store name of an external secret declared under key.
Sourcepub fn refresh_interval(&self) -> Duration
pub fn refresh_interval(&self) -> Duration
How often a driver-backed secret is checked for a new version.
Sourcepub fn is_client_side(&self) -> bool
pub fn is_client_side(&self) -> bool
Resolved where the deployer stands (file, environment), rather
than from the org’s store and the daemon’s key.
Sourcepub fn source_kind(&self) -> &'static str
pub fn source_kind(&self) -> &'static str
The source kind, for messages.
Trait Implementations§
Source§impl<'de> Deserialize<'de> for SecretDef
impl<'de> Deserialize<'de> for SecretDef
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Source§impl JsonSchema for SecretDef
impl JsonSchema for SecretDef
Source§fn schema_id() -> Cow<'static, str>
fn schema_id() -> Cow<'static, str>
Source§fn json_schema(generator: &mut SchemaGenerator) -> Schema
fn json_schema(generator: &mut SchemaGenerator) -> Schema
Source§fn inline_schema() -> bool
fn inline_schema() -> bool
$ref keyword. Read more