credential

package
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 8, 2026 License: MIT Imports: 4 Imported by: 0

Documentation

Overview

Package credential provides the small, in-memory host vault shared by AgentRay and consumers of agentcore.CredentialResolver. It has no infrastructure dependencies.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func ValidName

func ValidName(name string) bool

ValidName reports whether name is a legal credential name. It is the single source of truth for the {{cred:NAME}} naming rule, shared by the host-side secret store (storage.UpsertAgentSecret) so a name that cannot be stored can never become one that silently fails to resolve at run time.

Types

type Vault

type Vault struct {
	// contains filtered or unexported fields
}

Vault holds named secrets and resolves {{cred:NAME}} placeholders against them. Values go in via Put and only ever come back out substituted into a tool's argument string by Resolve. Formatting reports only the count; JSON cannot serialize the private map.

Safe for concurrent use: a run resolves placeholders while the host may still be loading the vault at startup.

func FromMap

func FromMap(m map[string]string) (*Vault, error)

FromMap builds a Vault from a name→value map, validating every entry through Put. It fails closed: a single invalid name or empty value rejects the whole map, so a misconfigured per-agent secret store surfaces at run start rather than as a silently-missing injection mid-run.

func NewVault

func NewVault() *Vault

NewVault returns an empty in-memory vault.

func (*Vault) GoString

func (v *Vault) GoString() string

func (*Vault) Len

func (v *Vault) Len() int

Len reports how many credentials are loaded.

func (*Vault) Names

func (v *Vault) Names() []string

Names returns the stored credential names (never the values), sorted-stable only by map iteration — for startup logging and tests. It is safe to log.

func (*Vault) Put

func (v *Vault) Put(name, value string) error

Put stores (or overwrites) a secret under name. The name must match [A-Za-z0-9_.-]{1,128}; an empty value is rejected so a misconfigured secret surfaces at load time, not as a silently-empty injection at run time.

func (*Vault) Resolve

func (v *Vault) Resolve(_ context.Context, args string) (string, error)

Resolve substitutes every {{cred:NAME}} placeholder in args with its secret value. It implements agentcore.CredentialResolver and fails closed: if a referenced credential is unknown, it returns an error (naming the missing credential, never a value) so the tool call is blocked and the model is told to correct course, rather than a bare placeholder reaching the tool. Args with no placeholder are returned unchanged with no allocation of the map.

func (*Vault) String

func (v *Vault) String() string

String and GoString prevent accidental value disclosure through diagnostic formatting.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL