Documentation
¶
Index ¶
- func CreateSecret(db *gorm.DB, settings *Secret) error
- func DecryptValue(value string) string
- func DeleteSecretByID(db *gorm.DB, id uint) error
- func EncryptValue(plaintext string) string
- func EncryptionKeyConfigured() bool
- func FilterSensitiveFields(obj interface{}) interface{}
- func FilterSesitiveFieldsArr(in interface{}) interface{}
- func GetOrCreateDefaultSecrets(db *gorm.DB) error
- func GetSecretReference(name string) string
- func GetValue(reference string, preserveRef bool) string
- func IsSecretReference(value string) bool
- func ReencryptLegacySecrets(db *gorm.DB) (int, error)
- func SetDBRef(db *gorm.DB)
- func SetEncryptionKey(key string)
- func UpdateSecret(db *gorm.DB, settings *Secret, encryptValue bool) error
- func WarnIfEncryptionUnconfigured() bool
- type Secret
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func CreateSecret ¶
CreateSecret creates a new Secret record in the database.
func DecryptValue ¶
DecryptValue decrypts a value that was encrypted with EncryptValue. Returns the decrypted plaintext, or the original value if not encrypted.
func DeleteSecretByID ¶
DeleteSecretByID deletes a Secret record from the database by ID.
func EncryptValue ¶
EncryptValue encrypts a plaintext string using the application's AES key. Returns the encrypted value or the original if encryption fails or is not configured.
func EncryptionKeyConfigured ¶
func EncryptionKeyConfigured() bool
EncryptionKeyConfigured reports whether a secrets encryption key is set, through SetEncryptionKey or the environment.
func FilterSensitiveFields ¶
func FilterSensitiveFields(obj interface{}) interface{}
func FilterSesitiveFieldsArr ¶
func FilterSesitiveFieldsArr(in interface{}) interface{}
func GetOrCreateDefaultSecrets ¶
GetOrCreateDefaultSecrets ensures default secrets exist in the database. This function creates OPENAI_KEY and ANTHROPIC_KEY secrets with empty values if they don't already exist, allowing users to fill in their API keys later.
func GetSecretReference ¶
GetSecretReference returns a secret reference string for a given name
func IsSecretReference ¶
IsSecretReference checks if a string is in the format $SECRET/NAME
func ReencryptLegacySecrets ¶
ReencryptLegacySecrets rewrites stored Secret rows that still use the legacy AES-CFB format to the current scrypt+AES-GCM scheme. Rows that are empty, already migrated, or fail to decrypt (e.g. written under a different key) are left untouched. Rows are processed in batches to bound memory usage, with each batch's updates applied in a single transaction. Returns the number of migrated rows.
func SetEncryptionKey ¶
func SetEncryptionKey(key string)
SetEncryptionKey sets the key that encrypts secrets at rest, taking the place of the TYK_AI_SECRET_KEY environment variable. An embedding host calls it before any secret is read or written.
func UpdateSecret ¶
UpdateSecret updates an existing Secret record in the database. When encryptValue is true, the Value field is encrypted before saving. Pass false when the Value already contains the stored (encrypted) value and should not be re-encrypted.
func WarnIfEncryptionUnconfigured ¶
func WarnIfEncryptionUnconfigured() bool
WarnIfEncryptionUnconfigured emits a prominent startup warning when the encryption key is not configured, so operators know stored secrets will be persisted as plaintext. Returns true when the key is configured.
Types ¶
type Secret ¶
type Secret struct {
gorm.Model
ID uint `gorm:"primaryKey" json:"id" access:"secrets"`
VarName string `json:"name"`
Value string `json:"value"`
// contains filtered or unexported fields
}
func GetSecretByID ¶
GetSecretByID retrieves a Secret record from the database by ID.
func GetSecretByVarName ¶
GetSecretByVarName retrieves a Secret record from the database by it's name.
func ListSecrets ¶
func (*Secret) HasValue ¶
HasValue reports whether the secret holds a non-empty value, without exposing it. Works on a row as stored (encrypted) and on one that has already been decrypted: an encrypted empty string is a real ciphertext, so the stored form has to be decrypted to know it is empty, while a decrypted value is simply checked for emptiness.
func (*Secret) PreserveReference ¶
func (s *Secret) PreserveReference()
PreserveReference sets the secret to return in reference format