keyring

package
v1.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: Apache-2.0 Imports: 16 Imported by: 0

Documentation

Overview

Package keyring encrypts secrets at rest with AES-256-GCM envelope encryption: every value gets a fresh data key, and the data key is encrypted ("wrapped") with the server's master key. Rotating the master key only requires re-wrapping data keys.

Index

Constants

View Source
const KeyCommandTimeout = 30 * time.Second

KeyCommandTimeout bounds STAMPEDE_MASTER_KEY_COMMAND.

Variables

View Source
var ErrNoKey = errors.New("no master key: set STAMPEDE_MASTER_KEY (32 bytes, base64) or STAMPEDE_MASTER_KEY_FILE")

ErrNoKey means no master key was configured.

Functions

func GenerateKey

func GenerateKey() string

GenerateKey returns a new random master key, base64 encoded.

Types

type Keyring

type Keyring struct {
	// contains filtered or unexported fields
}

Keyring holds the master key.

func FromEnv

func FromEnv() (*Keyring, error)

FromEnv reads STAMPEDE_MASTER_KEY (base64) or STAMPEDE_MASTER_KEY_FILE.

func New

func New(key []byte) (*Keyring, error)

New builds a keyring from a 32-byte key.

func (*Keyring) Derive

func (k *Keyring) Derive(purpose string, n int) []byte

Derive returns n bytes derived from the master key for one purpose (HKDF-SHA256 with the purpose as info). Different purposes give independent keys, and the master key cannot be recovered from them.

func (*Keyring) KeyID

func (k *Keyring) KeyID() string

KeyID identifies the master key (a short hash), stored with each secret so a rotation can find values wrapped with an older key.

func (*Keyring) Open

func (k *Keyring) Open(s Sealed, aad []byte) ([]byte, error)

Open decrypts a sealed value.

func (*Keyring) Seal

func (k *Keyring) Seal(plaintext, aad []byte) (Sealed, error)

Seal encrypts plaintext. aad binds the ciphertext to its context (for example the project and secret name) so it cannot be swapped elsewhere.

type Sealed

type Sealed struct {
	Ciphertext []byte // nonce || AES-GCM(dataKey, plaintext)
	WrappedKey []byte // nonce || AES-GCM(master, dataKey)
	KeyID      string
}

Sealed is an encrypted value.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL