Documentation
¶
Overview ¶
Package keystore resolves the Typesafe API key from a fixed chain of sources, first hit wins, and reports which source won.
Resolution order:
- env JEVKIT_API_KEY, then TYPESAFE_API_KEY
- env-file <workspace>/.env, parsed (never sourced) for the key line only
- command a stored command whose stdout is the key
- keychain the OS keychain (service "jevkit", account "TYPESAFE_API_KEY")
- file a 0600 plaintext file in the config dir (last resort)
A configured backend that fails does not fall through to a later one, with one exception: an unavailable keychain is skipped silently. Backend selection lives in jev-credentials.json (0600) in the config dir. Keys are never written under the workspace.
Index ¶
- Constants
- Variables
- func ConfigDir(getenv func(string) string) string
- func ReadKey(r io.Reader) (string, error)
- type Keyring
- type OSKeyring
- type Source
- type Store
- func (s *Store) Clear() error
- func (s *Store) EnvFilePath() string
- func (s *Store) Resolve(ctx context.Context) (string, Source, error)
- func (s *Store) SetCommand(command string) error
- func (s *Store) SetFile(key string) error
- func (s *Store) SetKeychain(key string) error
- func (s *Store) Source(ctx context.Context) Source
- func (s *Store) Status(ctx context.Context) string
Constants ¶
const ( // KeychainService and KeychainAccount identify the keychain entry. KeychainService = "jevkit" KeychainAccount = "TYPESAFE_API_KEY" )
Variables ¶
var ErrKeyringNotFound = errors.New("keystore: keychain entry not found")
ErrKeyringNotFound is returned by a Keyring when the entry does not exist. Any other Keyring error means the keychain is unavailable and is skipped.
var ErrNoKey = errors.New("keystore: no API key configured")
ErrNoKey means no source produced a key.
Functions ¶
Types ¶
type Keyring ¶
type Keyring interface {
Get(service, account string) (string, error)
Set(service, account, secret string) error
Delete(service, account string) error
}
Keyring is the OS keychain surface the store needs.
type OSKeyring ¶
type OSKeyring struct{}
OSKeyring is the Keyring backed by zalando/go-keyring.
type Store ¶
type Store struct {
// Getenv reads the environment; defaults to os.Getenv.
Getenv func(string) string
// Workspace is the workspace root whose .env is consulted.
Workspace string
// ConfigDir holds jev-credentials.json and the plaintext key file.
ConfigDir string
// Keyring is the keychain backend; defaults to OSKeyring.
Keyring Keyring
// Timeout bounds the stored command; JEVKIT_KEY_TIMEOUT_MS overrides the
// 4s default when Timeout is zero.
Timeout time.Duration
// Warn receives the plaintext-storage warning; defaults to os.Stderr.
Warn io.Writer
}
Store resolves and stores the API key. The zero value is not usable; use New.
func New ¶
New returns a Store for the given workspace root using the process environment, the default config dir and the OS keychain.
func (*Store) EnvFilePath ¶
EnvFilePath is the workspace dotenv path consulted by the env-file source.
func (*Store) Resolve ¶
Resolve returns the key and the source that supplied it. When a configured backend fails, the source is still reported alongside the error so callers can say which backend to fix; with nothing configured the error is ErrNoKey.
func (*Store) SetCommand ¶
SetCommand stores a command whose stdout is the key. No secret is stored.
func (*Store) SetFile ¶
SetFile stores key in a 0600 plaintext file and selects that backend, warning that the key is stored in plaintext.
func (*Store) SetKeychain ¶
SetKeychain stores key in the OS keychain and selects that backend.