Skip to main content

CredentialStore

Struct CredentialStore 

Source
pub struct CredentialStore {}
Expand description

Credential store abstraction

Implementations§

Source§

impl CredentialStore

Source

pub fn new() -> Self

Create a new credential store with automatic backend selection

Source

pub fn plaintext() -> Self

Create a store that always uses plaintext (no keyring). Useful for tests and for the explicit --allow-plaintext opt-in when no keyring is available.

Source

pub fn probe_writable(&self) -> Result<()>

Confirm the backend can actually hold a credential, by storing a throwaway value and reading it back.

The keyring availability check only reads, and a backend can answer a read and still refuse a write — a locked macOS keychain, a Windows credential store the session cannot write, keyutils in a container without CONFIG_KEYS. Callers about to create something they cannot recreate — a minted API key, whose secret is returned once — should ask here first.

What this does not establish: on Linux the backend is keyutils (see the keyring features in the workspace Cargo.toml), where the value lives in an in-memory kernel keyring. A write and read-back inside one process succeeds there even when the value will not be visible to the next redisctl run — the same absence Self::get_credential reports after a reboot.

Source

pub fn store_credential(&self, key: &str, value: &str) -> Result<String>

Store a credential value

Source

pub fn get_credential( &self, value: &str, env_var: Option<&str>, ) -> Result<String>

Retrieve a credential value

Resolution order:

  1. Check environment variables in order (if env vars provided)
  2. If value starts with “keyring:”, retrieve from keyring
  3. Otherwise, return the value as-is (plaintext)
Source

pub fn get_credential_with_env_vars( &self, value: &str, env_vars: Vec<&str>, ) -> Result<String>

Retrieve a credential value with support for multiple environment variable aliases.

Environment variables are checked in order, and the first set value wins.

Source

pub fn get_credential_with_environment( &self, value: &str, env_vars: &[&str], environment_overrides: EnvironmentOverrides, ) -> Result<String>

Retrieve a credential with an explicit environment override policy.

This is used by callers that load an explicit configuration file and require its credential values to be isolated from the process environment.

Source

pub fn delete_credential(&self, key: &str) -> Result<()>

Delete a credential from storage

Source

pub fn is_keyring_reference(value: &str) -> bool

Check if a value is a keyring reference

Source

pub fn storage_backend(&self) -> &str

Get the current storage backend

Trait Implementations§

Source§

impl Default for CredentialStore

Source§

fn default() -> Self

Returns the “default value” for a type. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> ErasedDestructor for T
where T: 'static,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more