Skip to main content

Signer

Struct Signer 

Source
pub struct Signer { /* private fields */ }
Expand description

The signing half, bound to the id agents know it by.

The key and its kid are only meaningful together, so nothing here hands out one without the other. Signing under an id whose public half agents hold for a different key produces command_signature_invalid on every machine at once — which reads as a fleet-wide forgery, not as the misconfiguration it is. Any API that lets the two be supplied separately is a way to reach that state, and resolve_kid on the generating side already refuses the other way in (two keys sharing one id).

Implementations§

Source§

impl Signer

Source

pub fn new(key: SigningKey, kid: impl Into<String>) -> Self

Source

pub fn from_secret(secret: &str, kid: &str) -> Result<Self, String>

Build from the encoded secret as it rests in the registry or the environment, rejecting an empty kid rather than signing under one.

An empty id is not a cosmetic problem: Kanade-Sig-Kid: "" matches no keyring entry, so every agent reports command_signature_unknown_key — the signal that is supposed to mean “this agent missed a rotation”. Producing it from a backend-side typo would train operators to ignore the one alarm the rotation procedure depends on.

Source

pub fn kid(&self) -> &str

Source

pub fn verifying_key(&self) -> VerifyingKey

Source

pub fn headers(&self, body: &[u8], at_ms: i64) -> SigHeaders

Sign body as of at_ms, yielding the headers to publish with it.

Trait Implementations§

Source§

impl Debug for Signer

Hand-written so the private key cannot reach a log line.

SigningKey derives Debug and prints its bytes, so a derived impl here would put the fleet’s crown jewel into any tracing call that formats the struct — including the ones nobody writes deliberately, like a #[derive( Debug)] on an enclosing type.

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more