Documentation
¶
Overview ¶
Package keyring encrypts secrets at rest with AES-256-GCM envelope encryption: every value gets a fresh data key, and the data key is encrypted ("wrapped") with the server's master key. Rotating the master key only requires re-wrapping data keys.
Index ¶
Constants ¶
const KeyCommandTimeout = 30 * time.Second
KeyCommandTimeout bounds STAMPEDE_MASTER_KEY_COMMAND.
Variables ¶
var ErrNoKey = errors.New("no master key: set STAMPEDE_MASTER_KEY (32 bytes, base64) or STAMPEDE_MASTER_KEY_FILE")
ErrNoKey means no master key was configured.
Functions ¶
func GenerateKey ¶
func GenerateKey() string
GenerateKey returns a new random master key, base64 encoded.
Types ¶
type Keyring ¶
type Keyring struct {
// contains filtered or unexported fields
}
Keyring holds the master key.
func (*Keyring) Derive ¶
Derive returns n bytes derived from the master key for one purpose (HKDF-SHA256 with the purpose as info). Different purposes give independent keys, and the master key cannot be recovered from them.
func (*Keyring) KeyID ¶
KeyID identifies the master key (a short hash), stored with each secret so a rotation can find values wrapped with an older key.