Documentation
¶
Index ¶
- Constants
- Variables
- func Decrypt(data []byte, password string) ([]byte, error)
- func Encrypt(plaintext []byte, password string) ([]byte, error)
- func EncryptFile(plaintext []byte, password string, metadata EncryptedFileMetadata) ([]byte, error)
- func EnsureInsideDir(baseDir, target string) error
- func RedactRepoURL(raw string) string
- func RejectSymlinkIfExists(path string) error
- func ValidateArtifactPrefix(prefix string) error
- func ValidateEncryptedRepositoryPaths(paths []string) error
- func ValidateObjectStorageOptions(options ObjectStorageOptions) error
- type AWSSecretsManagerOptions
- type AWSSecretsManagerStore
- type ArtifactStore
- type EncryptedFileMetadata
- type GitLabSecureFilesOptions
- type GitLabSecureFilesStore
- type GitStore
- func (g *GitStore) CheckEncryptedFileParent(relPath string) error
- func (g *GitStore) CheckEncryptedRepositoryPaths(planned []string) error
- func (g *GitStore) CheckNewEncryptedFile(relPath string) error
- func (g *GitStore) CheckWriteEncryptedFile(relPath string) error
- func (g *GitStore) Cleanup() error
- func (g *GitStore) Clone(ctx context.Context, allowCreate bool) error
- func (g *GitStore) CommitAndPush(ctx context.Context, message string) error
- func (g *GitStore) EncryptedFileSize(relPath string) (int64, error)
- func (g *GitStore) ListEncryptedFiles() ([]string, error)
- func (g *GitStore) ReadEncryptedArtifact(relPath string) ([]byte, error)
- func (g *GitStore) ReadEncryptedFile(relPath string, password string) ([]byte, error)
- func (g *GitStore) ReadEncryptedFileWithMetadata(relPath string, password string) ([]byte, EncryptedFileMetadata, error)
- func (g *GitStore) ReplaceEncryptedFile(relPath string, plaintext []byte, password string) error
- func (g *GitStore) ReplaceEncryptedFileWithMetadata(relPath string, plaintext []byte, password string, ...) error
- func (g *GitStore) WriteEncryptedArtifact(relPath string, ciphertext []byte) error
- func (g *GitStore) WriteEncryptedFile(relPath string, plaintext []byte, password string) error
- func (g *GitStore) WriteEncryptedFileWithMetadata(relPath string, plaintext []byte, password string, ...) error
- type ObjectStorageOptions
- type ObjectStorageRotationReport
- type ObjectStorageStore
- func (s *ObjectStorageStore) Fetch(ctx context.Context, store ArtifactStore) error
- func (s *ObjectStorageStore) Locator() string
- func (s *ObjectStorageStore) Publish(ctx context.Context, store ArtifactStore) error
- func (s *ObjectStorageStore) PublishRotation(ctx context.Context, store ArtifactStore, previous map[string][]byte) (ObjectStorageRotationReport, error)
- type RequestContextFunc
- type SecretsManagerAPI
Constants ¶
const EncryptedArtifactSuffix = ".enc"
EncryptedArtifactSuffix is the on-disk suffix of an encrypted signing artifact. Remote stores keep it so a stored object is never mistaken for plaintext signing material.
const MaxEncryptedArtifactBytes = maxEncryptedFileSize
MaxEncryptedArtifactBytes is the per-artifact ciphertext limit shared by the encrypted repository and every remote store.
Variables ¶
var ErrObjectStorageConflict = errors.New("object changed since it was fetched")
ErrObjectStorageConflict reports that an object changed after this store fetched it, so publishing would overwrite ciphertext that was never validated.
Functions ¶
func Encrypt ¶
Encrypt encrypts plaintext using AES-256-GCM with a password-derived key. Output format: salt (16 bytes) || nonce (12 bytes) || ciphertext+tag.
func EncryptFile ¶ added in v1.260816.0
func EncryptFile(plaintext []byte, password string, metadata EncryptedFileMetadata) ([]byte, error)
EncryptFile encrypts plaintext and authenticates the versioned metadata as AES-GCM additional data. The envelope is magic || metadata length || metadata JSON || salt || nonce || ciphertext+tag.
func EnsureInsideDir ¶
EnsureInsideDir checks that target stays inside baseDir and does not traverse any symlinked parent directories.
func RedactRepoURL ¶ added in v1.260813.0
RedactRepoURL removes credentials embedded in a repository URL so the remote can be named in errors, diagnostics, and structured output without leaking a token or password.
func RejectSymlinkIfExists ¶
RejectSymlinkIfExists rejects writes through an existing symlink path.
func ValidateArtifactPrefix ¶
ValidateArtifactPrefix checks the short path prefix that scopes signing artifacts inside a shared remote store.
func ValidateEncryptedRepositoryPaths ¶ added in v1.260816.0
ValidateEncryptedRepositoryPaths rejects path sets that cannot coexist on a Windows case-insensitive or normalization-insensitive macOS checkout. It normalizes canonically equivalent paths before applying the Unicode simple-fold classes behind strings.EqualFold. Exact duplicate canonical paths retain their existing update semantics.
func ValidateObjectStorageOptions ¶
func ValidateObjectStorageOptions(options ObjectStorageOptions) error
ValidateObjectStorageOptions checks the bucket, prefix, region, and endpoint without reading credentials or contacting the network.
Types ¶
type AWSSecretsManagerOptions ¶
type AWSSecretsManagerOptions struct {
// Region is the AWS region holding the secrets.
Region string
// Prefix scopes the artifacts this store owns inside the account.
Prefix string
// API overrides the SDK client in tests.
API SecretsManagerAPI
// MaxArtifacts bounds how many prefixed artifacts may be transported.
MaxArtifacts int
// RequestContext bounds one Secrets Manager request.
RequestContext RequestContextFunc
}
AWSSecretsManagerOptions configures an experimental AWS Secrets Manager store for already-encrypted signing artifacts.
type AWSSecretsManagerStore ¶
type AWSSecretsManagerStore struct {
// contains filtered or unexported fields
}
AWSSecretsManagerStore transports encrypted signing artifacts as base64 secret strings. It never receives the sync password and never decrypts an artifact.
func NewAWSSecretsManagerStore ¶
func NewAWSSecretsManagerStore(ctx context.Context, options AWSSecretsManagerOptions) (*AWSSecretsManagerStore, error)
NewAWSSecretsManagerStore validates the locator and resolves credentials from the standard AWS environment when no client is supplied.
func (*AWSSecretsManagerStore) Fetch ¶
func (s *AWSSecretsManagerStore) Fetch(ctx context.Context, store ArtifactStore) error
Fetch downloads every encrypted artifact under the configured prefix into the local ciphertext store.
func (*AWSSecretsManagerStore) Locator ¶
func (s *AWSSecretsManagerStore) Locator() string
Locator returns a description of the configured store. It contains no credential material.
func (*AWSSecretsManagerStore) Publish ¶
func (s *AWSSecretsManagerStore) Publish(ctx context.Context, store ArtifactStore) error
Publish stores every local encrypted artifact as a base64 secret string. Secrets outside the configured prefix are never inspected, and no secret is ever deleted.
type ArtifactStore ¶
type ArtifactStore interface {
ListEncryptedFiles() ([]string, error)
ReadEncryptedArtifact(relPath string) ([]byte, error)
WriteEncryptedArtifact(relPath string, ciphertext []byte) error
}
ArtifactStore is the ciphertext-only view of a local encrypted signing tree. Remote stores transport artifacts through this interface and never see the sync password or any decrypted byte.
type EncryptedFileMetadata ¶ added in v1.260816.0
type EncryptedFileMetadata struct {
Version int `json:"version"`
Kind string `json:"kind,omitempty"`
RelativePath string `json:"relativePath,omitempty"`
Sensitive bool `json:"sensitive,omitempty"`
CertificateSHA256 string `json:"certificateSha256,omitempty"`
TeamID string `json:"teamId,omitempty"`
BundleID string `json:"bundleId,omitempty"`
ProfileType string `json:"profileType,omitempty"`
ProfileResourceID string `json:"profileResourceId,omitempty"`
ProfileUUID string `json:"profileUuid,omitempty"`
ProfilePath string `json:"profilePath,omitempty"`
ProfileSHA256 string `json:"profileSha256,omitempty"`
KDF string `json:"kdf,omitempty"`
ScryptN int `json:"scryptN,omitempty"`
ScryptR int `json:"scryptR,omitempty"`
ScryptP int `json:"scryptP,omitempty"`
}
EncryptedFileMetadata is authenticated with a versioned encrypted signing artifact. It contains no secret material.
func DecryptFile ¶ added in v1.260816.0
func DecryptFile(data []byte, password string) ([]byte, EncryptedFileMetadata, error)
DecryptFile decrypts a versioned envelope. Legacy unversioned ciphertext remains readable and returns zero-valued metadata.
type GitLabSecureFilesOptions ¶
type GitLabSecureFilesOptions struct {
// Host is an https base URL. It defaults to https://gitlab.com.
Host string
// ProjectID is the numeric GitLab project ID.
ProjectID string
// Prefix scopes the artifacts this store owns inside the project.
Prefix string
// Token authenticates API requests. It is sent only as a request header.
Token string
// HTTPClient overrides the default client in tests.
HTTPClient *http.Client
// MaxArtifacts bounds how many prefixed artifacts may be transported.
MaxArtifacts int
// RequestContext bounds one list, download, or delete request.
RequestContext RequestContextFunc
// UploadContext bounds one upload request.
UploadContext RequestContextFunc
}
GitLabSecureFilesOptions configures an experimental GitLab Secure Files store for already-encrypted signing artifacts.
type GitLabSecureFilesStore ¶
type GitLabSecureFilesStore struct {
// contains filtered or unexported fields
}
GitLabSecureFilesStore transports encrypted signing artifacts through the GitLab Secure Files API. It never receives the sync password and never decrypts an artifact.
func NewGitLabSecureFilesStore ¶
func NewGitLabSecureFilesStore(options GitLabSecureFilesOptions) (*GitLabSecureFilesStore, error)
NewGitLabSecureFilesStore validates the locator and credentials of a GitLab Secure Files store.
func (*GitLabSecureFilesStore) Fetch ¶
func (s *GitLabSecureFilesStore) Fetch(ctx context.Context, store ArtifactStore) error
Fetch downloads every encrypted artifact under the configured prefix into the local ciphertext store.
func (*GitLabSecureFilesStore) Locator ¶
func (s *GitLabSecureFilesStore) Locator() string
Locator returns a redacted description of the configured store.
func (*GitLabSecureFilesStore) Publish ¶
func (s *GitLabSecureFilesStore) Publish(ctx context.Context, store ArtifactStore) error
Publish uploads every local encrypted artifact that the remote store does not already hold byte-for-byte. Secure files outside the configured prefix are never inspected, replaced, or deleted.
type GitStore ¶
type GitStore struct {
RepoURL string
LocalDir string
Branch string
// contains filtered or unexported fields
}
GitStore manages an encrypted git repository of signing assets.
func (*GitStore) CheckEncryptedFileParent ¶ added in v1.260816.0
CheckEncryptedFileParent validates an encrypted artifact's future parent layout without assuming its final profile-specific name is known yet.
func (*GitStore) CheckEncryptedRepositoryPaths ¶ added in v1.260816.0
CheckEncryptedRepositoryPaths validates planned paths together with every existing encrypted artifact before a push writes any repository files.
func (*GitStore) CheckNewEncryptedFile ¶ added in v1.260816.0
CheckNewEncryptedFile performs the rooted, non-mutating destination checks used before publishing a new versioned encrypted artifact.
func (*GitStore) CheckWriteEncryptedFile ¶ added in v1.260816.0
CheckWriteEncryptedFile performs the non-mutating rooted checks used before replacing or creating a legacy encrypted signing artifact.
func (*GitStore) Clone ¶
Clone clones the git repo. If allowCreate is true (push mode), falls back to initializing an empty repo when the branch doesn't exist. If false (pull mode), fails when the branch is missing.
func (*GitStore) CommitAndPush ¶
CommitAndPush stages all changes, commits, and pushes.
func (*GitStore) EncryptedFileSize ¶ added in v1.260816.0
EncryptedFileSize returns the size of a regular no-follow encrypted artifact.
func (*GitStore) ListEncryptedFiles ¶
ListEncryptedFiles returns relative paths (without .enc) of all encrypted files.
func (*GitStore) ReadEncryptedArtifact ¶
ReadEncryptedArtifact returns the raw ciphertext of an encrypted artifact without decrypting it.
func (*GitStore) ReadEncryptedFile ¶
ReadEncryptedFile reads and decrypts a file from the repo. Rejects symlinks to prevent reading outside the clone directory.
func (*GitStore) ReadEncryptedFileWithMetadata ¶ added in v1.260816.0
func (g *GitStore) ReadEncryptedFileWithMetadata(relPath string, password string) ([]byte, EncryptedFileMetadata, error)
ReadEncryptedFileWithMetadata reads either a versioned envelope or a legacy encrypted file.
func (*GitStore) ReplaceEncryptedFile ¶ added in v1.260831.0
ReplaceEncryptedFile creates or replaces a legacy encrypted artifact while preserving its existing file mode when present. Replacement is atomic on platforms where rename replaces an existing destination; on Windows, the original is restored if publishing the replacement fails.
func (*GitStore) ReplaceEncryptedFileWithMetadata ¶ added in v1.260816.0
func (g *GitStore) ReplaceEncryptedFileWithMetadata(relPath string, plaintext []byte, password string, metadata EncryptedFileMetadata) error
ReplaceEncryptedFileWithMetadata atomically creates or replaces a versioned encrypted artifact after the caller has validated its scope.
func (*GitStore) WriteEncryptedArtifact ¶
WriteEncryptedArtifact stores raw ciphertext fetched from a remote store. The bytes are written unchanged so the existing envelope, metadata, and password checks decide whether they are usable.
func (*GitStore) WriteEncryptedFile ¶
WriteEncryptedFile writes an encrypted file into the repo. Validates that the resolved path stays inside LocalDir to prevent symlink escapes.
func (*GitStore) WriteEncryptedFileWithMetadata ¶ added in v1.260816.0
func (g *GitStore) WriteEncryptedFileWithMetadata(relPath string, plaintext []byte, password string, metadata EncryptedFileMetadata) error
WriteEncryptedFileWithMetadata writes a versioned encrypted file whose non-secret metadata is authenticated with the ciphertext.
type ObjectStorageOptions ¶
type ObjectStorageOptions struct {
// Bucket names the bucket holding the artifacts.
Bucket string
// Prefix optionally scopes the artifacts inside the bucket. One trailing
// slash is accepted; an empty prefix uses the bucket root.
Prefix string
// Region overrides the region from the standard AWS configuration.
Region string
// Endpoint optionally selects an S3-compatible HTTPS origin, addressed
// with path-style requests.
Endpoint string
// MaxArtifacts bounds how many prefixed artifacts may be transported.
MaxArtifacts int
// RequestContext bounds one object storage request.
RequestContext RequestContextFunc
}
ObjectStorageOptions configures an experimental S3-compatible object storage store for already-encrypted signing artifacts.
type ObjectStorageRotationReport ¶
type ObjectStorageRotationReport struct {
// LeftoverStagedKeys lists staged copies that could not be deleted after
// a successful swap. They are ignored by fetches and safe to delete.
LeftoverStagedKeys []string
}
ObjectStorageRotationReport describes a completed rotation.
type ObjectStorageStore ¶
type ObjectStorageStore struct {
// contains filtered or unexported fields
}
ObjectStorageStore transports encrypted signing artifacts as objects laid out exactly like the encrypted Git working tree. It never receives the sync password and never decrypts an artifact.
func NewObjectStorageStore ¶
func NewObjectStorageStore(ctx context.Context, options ObjectStorageOptions) (*ObjectStorageStore, error)
NewObjectStorageStore validates the locator and resolves credentials and the region from the standard AWS configuration chain: environment, shared configuration files, web identity, and container or instance metadata.
func (*ObjectStorageStore) Fetch ¶
func (s *ObjectStorageStore) Fetch(ctx context.Context, store ArtifactStore) error
Fetch downloads every encrypted artifact under the prefix into the local ciphertext store and records each object's generation for later conditional writes.
func (*ObjectStorageStore) Locator ¶
func (s *ObjectStorageStore) Locator() string
Locator returns an s3:// description of the bucket and prefix. It contains no credential material and omits any custom endpoint host.
func (*ObjectStorageStore) Publish ¶
func (s *ObjectStorageStore) Publish(ctx context.Context, store ArtifactStore) error
Publish writes every changed local artifact. A new object is created only if no object exists at its key, and an existing object is replaced only if it still has the generation observed by Fetch, so a concurrent writer's ciphertext is never overwritten. Objects outside the prefix are never inspected, and no object is deleted.
func (*ObjectStorageStore) PublishRotation ¶
func (s *ObjectStorageStore) PublishRotation(ctx context.Context, store ArtifactStore, previous map[string][]byte) (ObjectStorageRotationReport, error)
PublishRotation replaces every fetched artifact with its re-encrypted local ciphertext in three phases:
- Stage: every new ciphertext is written to a create-only staged key next to its live key. A failure removes the staged copies and leaves every live artifact unchanged.
- Verify: every live object must still have the generation observed by Fetch. A change aborts the rotation before any live write.
- Swap: each live object is replaced only if it still has the observed generation. If a swap fails, the already replaced artifacts are restored from previous, again conditionally. If restoration also fails, the staged copies are kept and the error lists which artifacts use the new password and how to finish the rotation.
Staged copies are deleted after a successful swap or a complete rollback. previous must hold the fetched ciphertext of every artifact.
type RequestContextFunc ¶
RequestContextFunc bounds one outbound request to a remote store. Commands pass the shared CLI timeout helpers so remote stores obey the same request budget as App Store Connect calls.
type SecretsManagerAPI ¶
type SecretsManagerAPI interface {
ListSecrets(ctx context.Context, params *secretsmanager.ListSecretsInput, optFns ...func(*secretsmanager.Options)) (*secretsmanager.ListSecretsOutput, error)
GetSecretValue(ctx context.Context, params *secretsmanager.GetSecretValueInput, optFns ...func(*secretsmanager.Options)) (*secretsmanager.GetSecretValueOutput, error)
CreateSecret(ctx context.Context, params *secretsmanager.CreateSecretInput, optFns ...func(*secretsmanager.Options)) (*secretsmanager.CreateSecretOutput, error)
PutSecretValue(ctx context.Context, params *secretsmanager.PutSecretValueInput, optFns ...func(*secretsmanager.Options)) (*secretsmanager.PutSecretValueOutput, error)
}
SecretsManagerAPI is the subset of AWS Secrets Manager used to transport encrypted signing artifacts. Tests substitute a stub so no test dials AWS.
Source Files
¶
Directories
¶
| Path | Synopsis |
|---|---|
|
Package objectstoretest provides an in-process, path-style S3-compatible server for tests that exercise the signing sync object storage backend.
|
Package objectstoretest provides an in-process, path-style S3-compatible server for tests that exercise the signing sync object storage backend. |