pub struct Signer { /* private fields */ }Expand description
The signing half, bound to the id agents know it by.
The key and its kid are only meaningful together, so nothing here hands
out one without the other. Signing under an id whose public half agents
hold for a different key produces command_signature_invalid on every
machine at once — which reads as a fleet-wide forgery, not as the
misconfiguration it is. Any API that lets the two be supplied separately is
a way to reach that state, and resolve_kid on the generating side already
refuses the other way in (two keys sharing one id).
Implementations§
Source§impl Signer
impl Signer
pub fn new(key: SigningKey, kid: impl Into<String>) -> Self
Sourcepub fn from_secret(secret: &str, kid: &str) -> Result<Self, String>
pub fn from_secret(secret: &str, kid: &str) -> Result<Self, String>
Build from the encoded secret as it rests in the registry or the
environment, rejecting an empty kid rather than signing under one.
An empty id is not a cosmetic problem: Kanade-Sig-Kid: "" matches no
keyring entry, so every agent reports command_signature_unknown_key —
the signal that is supposed to mean “this agent missed a rotation”.
Producing it from a backend-side typo would train operators to ignore
the one alarm the rotation procedure depends on.
pub fn kid(&self) -> &str
pub fn verifying_key(&self) -> VerifyingKey
Sourcepub fn headers(&self, body: &[u8], at_ms: i64) -> SigHeaders
pub fn headers(&self, body: &[u8], at_ms: i64) -> SigHeaders
Sign body as of at_ms, yielding the headers to publish with it.
Trait Implementations§
Source§impl Debug for Signer
Hand-written so the private key cannot reach a log line.
impl Debug for Signer
Hand-written so the private key cannot reach a log line.
SigningKey derives Debug and prints its bytes, so a derived impl here
would put the fleet’s crown jewel into any tracing call that formats the
struct — including the ones nobody writes deliberately, like a #[derive( Debug)] on an enclosing type.