Skip to main content

Barrier

Struct Barrier 

Source
pub struct Barrier<B: StorageBackend> { /* private fields */ }
Expand description

Wraps a raw StorageBackend, transparently AEAD-encrypting/decrypting values. Paths are left in plaintext (same as Vault’s own barrier).

Implementations§

Source§

impl<B: StorageBackend> Barrier<B>

Source

pub fn new(inner: B, aead: Arc<dyn Aead>) -> Self

Trait Implementations§

Source§

impl<B: StorageBackend> KeyRotation for Barrier<B>

Source§

fn rewrap_all<'life0, 'async_trait>( &'life0 self, ) -> Pin<Box<dyn Future<Output = StorageResult<RewrapReport>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait,

Rewraps every value not already sealed under the active key. Idempotent and safe to re-run: a second pass reports everything as unchanged.
Source§

fn active_key_id(&self) -> String

The active key’s derived id, so an operator can confirm which key a replica is actually sealing with.
Source§

impl<B: StorageBackend> StorageBackend for Barrier<B>

Source§

fn get<'life0, 'life1, 'async_trait>( &'life0 self, path: &'life1 str, ) -> Pin<Box<dyn Future<Output = StorageResult<Option<StorageEntry>>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Source§

fn put<'life0, 'life1, 'async_trait>( &'life0 self, path: &'life1 str, entry: StorageEntry, ) -> Pin<Box<dyn Future<Output = StorageResult<()>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Source§

fn delete<'life0, 'life1, 'async_trait>( &'life0 self, path: &'life1 str, ) -> Pin<Box<dyn Future<Output = StorageResult<()>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Source§

fn list<'life0, 'life1, 'async_trait>( &'life0 self, prefix: &'life1 str, ) -> Pin<Box<dyn Future<Output = StorageResult<Vec<String>>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Source§

fn ping<'life0, 'async_trait>( &'life0 self, ) -> Pin<Box<dyn Future<Output = StorageResult<()>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait,

Cheap liveness probe for the health endpoint. It must stay cheap: a load balancer calls it constantly, against every replica, forever.
Source§

fn list_expired<'life0, 'life1, 'async_trait>( &'life0 self, prefix: &'life1 str, now: DateTime<Utc>, ) -> Pin<Box<dyn Future<Output = StorageResult<Vec<String>>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Paths under prefix whose expires_at has already passed. Read more
Source§

fn replace_if_unchanged<'life0, 'life1, 'life2, 'async_trait>( &'life0 self, path: &'life1 str, expected: &'life2 [u8], entry: StorageEntry, ) -> Pin<Box<dyn Future<Output = StorageResult<bool>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait, 'life2: 'async_trait,

Replaces path’s value only if it still holds exactly expected, returning false when it changed underneath. Read more
Source§

fn try_acquire_lock<'life0, 'life1, 'async_trait>( &'life0 self, key: &'life1 str, ) -> Pin<Box<dyn Future<Output = StorageResult<bool>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Best-effort cross-process mutual exclusion, so exactly one replica runs a singleton background task. Granting unconditionally is correct for a single-node or in-memory backend, which is why that is the default. Read more

Auto Trait Implementations§

§

impl<B> !RefUnwindSafe for Barrier<B>

§

impl<B> !UnwindSafe for Barrier<B>

§

impl<B> Freeze for Barrier<B>
where B: Freeze,

§

impl<B> Send for Barrier<B>

§

impl<B> Sync for Barrier<B>

§

impl<B> Unpin for Barrier<B>
where B: Unpin,

§

impl<B> UnsafeUnpin for Barrier<B>
where B: UnsafeUnpin,

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more