Skip to main content

Module credentials

Module credentials 

Source
Expand description

Named credential custody (ADR-192). Resolution never exposes material to packs.

Structs§

CredentialConfig
Closed named references. Material is resolved by providers and never stored in config.
CredentialMaterial
Owned secret bytes, zeroized on drop. Only runtime custody consumers can inspect them.
CredentialRegistry
Validated references plus provider implementations, without serialized secret values.
VisibilityReceiptConfig
Receipt key IDs and credential references; this table contains no key bytes.
VisibilityReceiptKeyConfig

Enums§

CredentialCacheLifetime
Maximum lifetime for a provider’s cached resolution.
CredentialError
Errors contain credential references and fixed reasons, never provider material or causes.
CredentialKind

Traits§

CredentialProvider
Downstream hosts register custody adapters here; env is the only shipped adapter.