pub struct KeyVault { /* private fields */ }Expand description
In-memory key vault.
The vault is the entry point for everything key-vault does. Application
code constructs one via KeyVaultBuilder, registers keys against it, and
receives KeyHandles in return. The vault itself is
cheap to clone (it is Arc-backed internally) and safe to share across
threads.
Key registration, access, rotation, and recovery are introduced in later phases. This skeleton exposes only the public shape — construction, cloning, and the lock-out indicator — so that downstream crates can wire against it now.
Implementations§
Source§impl KeyVault
impl KeyVault
Sourcepub fn is_locked_out(&self) -> bool
pub fn is_locked_out(&self) -> bool
Returns true if the vault is in lock-out state.
Lock-out is the SecurityMonitor’s response
to repeated failures: once the threshold is crossed, access to every
key in the vault is denied until the configured recovery condition is
met. In Phase 0.2 the lock-out flag exists but is never set; Phase 0.8
connects it to monitor events.
Sourcepub fn config(&self) -> &VaultConfig
pub fn config(&self) -> &VaultConfig
Snapshot of the vault’s configuration.