Expand description
Shared entropy primitives for every locally-minted credential.
The auto-register flow (install id + registration secret) and the local API (bearer token) all need unpredictable values: an attacker who can guess any of them can impersonate the worker or drive its GPU. Centralising the OS-CSPRNG access here means there is exactly one audited path instead of per-module copies drifting apart.
Functionsยง
- new_
secret_ hex - 32 bytes of randomness = 64 hex chars (256 bits of entropy).
- new_
uuid - UUIDv4-ish without pulling in the
uuidcrate: 16 random bytes formatted as 8-4-4-4-12. - rand_
bytes - Fill
Nbytes from the OS cryptographically-secure RNG via thegetrandomcrate (getrandom(2)//dev/urandomon Linux,getentropyon macOS,BCryptGenRandomon Windows). - sha256_
hex - Hex-encoded SHA-256 of
input. Used to send only the hash of a locally-held secret over the wire (auto-register).