Skip to main content

SecretDef

Struct SecretDef 

Source
pub struct SecretDef {
    pub file: Option<String>,
    pub environment: Option<String>,
    pub external: bool,
    pub name: Option<String>,
    pub age: Option<String>,
    pub driver: Option<String>,
    pub refresh: Option<String>,
    pub on_change: Option<OnChange>,
    pub rotate: Option<Vec<String>>,
}
Expand description

Where a secret’s value comes from. Exactly one source.

Fields§

§file: Option<String>

A host file holding the value (relative to the compose file).

§environment: Option<String>

An environment variable of whoever deploys the file (isb up, or the client calling isb stack deploy).

§external: bool

The secret already exists in the org’s secret store (isb secret create), under name (default: the key).

§name: Option<String>

With external: the store’s name for it. With driver: the driver’s reference (a 1Password op:// path, say).

§age: Option<String>

The value, age-encrypted to the daemon’s recipients (isb secret encrypt): ASCII-armored, or base64 of the binary format.

§driver: Option<String>

Read through this secrets driver, from name.

§refresh: Option<String>

With driver: how often isb serve checks the driver for a new version (30m, 1h; default 1h). A new version rolls the services using it.

§on_change: Option<OnChange>

What a new version does to the services using it under isb serve: roll (default), restart or none. A service’s own reference (secrets: [{source, on_change}], {secret, on_change}) overrides it.

§rotate: Option<Vec<String>>

Under isb serve: argv run in one running replica of each service using the secret when it gets a new version, before any replica is given it, to make the new value take effect where the old one is stored (a database user’s password). It reads the new value on stdin and runs with the replica’s own environment, which still holds the old one. A failure stops the change: isb secret set stores nothing, and a driver’s new version is not taken up.

Implementations§

Source§

impl SecretDef

Source

pub fn validate(&self) -> Result<(), String>

Check that exactly one source is given: file, environment, external, age, or driver with name.

Source

pub fn store_name<'a>(&'a self, key: &'a str) -> Option<&'a str>

The store name of an external secret declared under key.

Source

pub fn refresh_interval(&self) -> Duration

How often a driver-backed secret is checked for a new version.

Source

pub fn is_client_side(&self) -> bool

Resolved where the deployer stands (file, environment), rather than from the org’s store and the daemon’s key.

Source

pub fn source_kind(&self) -> &'static str

The source kind, for messages.

Trait Implementations§

Source§

impl Clone for SecretDef

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for SecretDef

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for SecretDef

Source§

fn default() -> Self

Returns the “default value” for a type. Read more
Source§

impl<'de> Deserialize<'de> for SecretDef

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl JsonSchema for SecretDef

Source§

fn schema_name() -> Cow<'static, str>

The name of the generated JSON Schema. Read more
Source§

fn schema_id() -> Cow<'static, str>

Returns a string that uniquely identifies the schema produced by this type. Read more
Source§

fn json_schema(generator: &mut SchemaGenerator) -> Schema

Generates a JSON Schema for this type. Read more
Source§

fn inline_schema() -> bool

Whether JSON Schemas generated for this type should be included directly in parent schemas, rather than being re-used where possible using the $ref keyword. Read more
Source§

impl PartialEq for SecretDef

Source§

fn eq(&self, other: &Self) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl Serialize for SecretDef

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more
Source§

impl StructuralPartialEq for SecretDef

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> AnyEq for T
where T: Any + PartialEq,

Source§

fn equals(&self, other: &(dyn Any + 'static)) -> bool

Source§

fn as_any(&self) -> &(dyn Any + 'static)

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V