pub struct KeyVaultBuilder { /* private fields */ }Expand description
Fluent builder for KeyVault.
The builder is the only way to construct a vault; the inherent
KeyVault::new constructor is intentionally not provided so that future
required configuration cannot be silently bypassed.
Implementations§
Source§impl KeyVaultBuilder
impl KeyVaultBuilder
Sourcepub fn new() -> Self
pub fn new() -> Self
Start a new builder with default configuration and a default-range
StandardFragmenter.
Sourcepub fn normalize_with_blake3(self, enabled: bool) -> Self
pub fn normalize_with_blake3(self, enabled: bool) -> Self
Enable or disable BLAKE3 normalization of input key material.
Default: true. Disabling normalization preserves the original byte
pattern of the key in storage, which can leak format cues (DER
envelopes, PEM markers, ASCII-armored data). Disable only when you
have a specific reason to preserve the original bytes.
Sourcepub fn with_chunk_range(self, min: usize, max: usize) -> Self
pub fn with_chunk_range(self, min: usize, max: usize) -> Self
Customize the fragmenter chunk-size range.
Defaults are documented on StandardFragmenter::new. min is
clamped to >= 1 and max to >= min. Calling this replaces any
previously-configured chunk range and resets the decoy strategy to
None; configure decoy after this call.
Sourcepub fn with_decoy<D>(self, decoy: D) -> Selfwhere
D: DecoyStrategy + 'static,
pub fn with_decoy<D>(self, decoy: D) -> Selfwhere
D: DecoyStrategy + 'static,
Attach a Layer-4 decoy strategy to the underlying fragmenter.
When set, every KeyVault::fragment call also produces decoy chunks
from the strategy. Decoys are interleaved with real chunks via the
same Fisher-Yates shuffle and are skipped by defragment. See
StandardFragmenter::with_decoy for details on chunk-count and
size selection.
Use SelfReferenceDecoy for the
strongest statistical indistinguishability (recommended default);
KeyDerivedDecoy for BLAKE3-XOF–derived
CSPRNG-like output;
RandomDecoy for raw CSPRNG output.
Trait Implementations§
Source§impl Clone for KeyVaultBuilder
impl Clone for KeyVaultBuilder
Source§fn clone(&self) -> KeyVaultBuilder
fn clone(&self) -> KeyVaultBuilder
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more