pub struct KeyVault { /* private fields */ }Expand description
In-memory key vault.
The vault is the entry point for everything key-vault does. Application
code constructs one via KeyVaultBuilder, hands it RawKey values
to be fragmented, and (in later phases) receives
KeyHandles in return. The vault itself is cheap to
clone (it is Arc-backed internally) and safe to share across threads.
In Phase 0.3 the vault exposes KeyVault::fragment and
KeyVault::defragment convenience methods that route through the
configured normalizer and StandardFragmenter. The full named-key
registry arrives in Phase 0.9.
Implementations§
Source§impl KeyVault
impl KeyVault
Sourcepub fn is_locked_out(&self) -> bool
pub fn is_locked_out(&self) -> bool
Returns true if the vault is in lock-out state.
Lock-out is the SecurityMonitor’s response
to repeated failures: once the threshold is crossed, access to every
key in the vault is denied until the configured recovery condition is
met. In Phase 0.2 the lock-out flag exists but is never set; Phase 0.8
connects it to monitor events.
Sourcepub fn config(&self) -> &VaultConfig
pub fn config(&self) -> &VaultConfig
Snapshot of the vault’s configuration.
Sourcepub fn fragment(&self, key: &RawKey) -> Result<Fragments>
pub fn fragment(&self, key: &RawKey) -> Result<Fragments>
Fragment a raw key through the configured normalizer, codex, and fragmenter.
The returned Fragments is opaque; pass it back to
KeyVault::defragment to recover the (normalized + codex-encoded)
bytes inverse-transformed.
§Pipeline
key → blake3_normalize (optional) → codex.encode (optional) → fragmenter.fragment → Fragments§Errors
Returns whatever the underlying FragmentStrategy surfaces — in
practice an Error::Fragment for a
zero-length input.
Sourcepub fn defragment(&self, fragments: &Fragments) -> Result<RawKey>
pub fn defragment(&self, fragments: &Fragments) -> Result<RawKey>
Reassemble fragments produced by KeyVault::fragment.
Inverts the codex transformation (if configured) so the recovered
bytes are the normalized key (or the original raw key if
normalization is off). Defragmentation itself is delegated to the
configured FragmentStrategy.
§Errors
Returns Error::Defragment when the
supplied fragments do not match the configured fragmenter’s layout.