Skip to main content

Module secrets

Module secrets 

Source
Expand description

Shared entropy primitives for every locally-minted credential.

The auto-register flow (install id + registration secret) and the local API (bearer token) all need unpredictable values: an attacker who can guess any of them can impersonate the worker or drive its GPU. Centralising the OS-CSPRNG access here means there is exactly one audited path instead of per-module copies drifting apart.

Functionsยง

new_secret_hex
32 bytes of randomness = 64 hex chars (256 bits of entropy).
new_uuid
UUIDv4-ish without pulling in the uuid crate: 16 random bytes formatted as 8-4-4-4-12.
rand_bytes
Fill N bytes from the OS cryptographically-secure RNG via the getrandom crate (getrandom(2) / /dev/urandom on Linux, getentropy on macOS, BCryptGenRandom on Windows).
sha256_hex
Hex-encoded SHA-256 of input. Used to send only the hash of a locally-held secret over the wire (auto-register).