pub struct CredentialStore {}Expand description
Credential store abstraction
Implementations§
Source§impl CredentialStore
impl CredentialStore
Sourcepub fn plaintext() -> Self
pub fn plaintext() -> Self
Create a store that always uses plaintext (no keyring). Useful for tests and for the
explicit --allow-plaintext opt-in when no keyring is available.
Sourcepub fn probe_writable(&self) -> Result<()>
pub fn probe_writable(&self) -> Result<()>
Confirm the backend can actually hold a credential, by storing a throwaway value and reading it back.
The keyring availability check only reads, and a backend can answer a read and
still refuse a write — a locked macOS keychain, a Windows credential store the session
cannot write, keyutils in a container without CONFIG_KEYS. Callers about to create
something they cannot recreate — a minted API key, whose secret is returned once — should
ask here first.
What this does not establish: on Linux the backend is keyutils (see the keyring
features in the workspace Cargo.toml), where the value lives in an in-memory kernel
keyring. A write and read-back inside one process succeeds there even when the value will
not be visible to the next redisctl run — the same absence Self::get_credential
reports after a reboot.
Sourcepub fn store_credential(&self, key: &str, value: &str) -> Result<String>
pub fn store_credential(&self, key: &str, value: &str) -> Result<String>
Store a credential value
Sourcepub fn get_credential(
&self,
value: &str,
env_var: Option<&str>,
) -> Result<String>
pub fn get_credential( &self, value: &str, env_var: Option<&str>, ) -> Result<String>
Retrieve a credential value
Resolution order:
- Check environment variables in order (if env vars provided)
- If value starts with “keyring:”, retrieve from keyring
- Otherwise, return the value as-is (plaintext)
Sourcepub fn get_credential_with_env_vars(
&self,
value: &str,
env_vars: Vec<&str>,
) -> Result<String>
pub fn get_credential_with_env_vars( &self, value: &str, env_vars: Vec<&str>, ) -> Result<String>
Retrieve a credential value with support for multiple environment variable aliases.
Environment variables are checked in order, and the first set value wins.
Sourcepub fn get_credential_with_environment(
&self,
value: &str,
env_vars: &[&str],
environment_overrides: EnvironmentOverrides,
) -> Result<String>
pub fn get_credential_with_environment( &self, value: &str, env_vars: &[&str], environment_overrides: EnvironmentOverrides, ) -> Result<String>
Retrieve a credential with an explicit environment override policy.
This is used by callers that load an explicit configuration file and require its credential values to be isolated from the process environment.
Sourcepub fn delete_credential(&self, key: &str) -> Result<()>
pub fn delete_credential(&self, key: &str) -> Result<()>
Delete a credential from storage
Sourcepub fn is_keyring_reference(value: &str) -> bool
pub fn is_keyring_reference(value: &str) -> bool
Check if a value is a keyring reference
Sourcepub fn storage_backend(&self) -> &str
pub fn storage_backend(&self) -> &str
Get the current storage backend