Documentation
¶
Overview ¶
Package secret provides unified access to secret storage (OpenBao / HashiCorp Vault).
Index ¶
- func BuildSshKeySecretPath(nsId, sshKeyId string) string
- func CheckStatus(ctx context.Context) model.OpenBaoStatusInfo
- func DeleteSecret(ctx context.Context, path string) error
- func DeleteSshKey(ctx context.Context, nsId, sshKeyId string) error
- func GetSshKey(ctx context.Context, nsId, sshKeyId string) (string, error)
- func InvalidateSecretCache(path string)
- func IsCasConflict(err error) bool
- func ReadSecret(ctx context.Context, path string) (map[string]any, error)
- func SaveSshKey(ctx context.Context, nsId, sshKeyId, privateKey string) error
- func WriteSecret(ctx context.Context, path string, data map[string]any) error
- func WriteSecretIfAbsent(ctx context.Context, path string, data map[string]any) (created bool, err error)
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func BuildSshKeySecretPath ¶
BuildSshKeySecretPath builds the OpenBao secret path for a given SSH key.
func CheckStatus ¶
func CheckStatus(ctx context.Context) model.OpenBaoStatusInfo
CheckStatus verifies that the OpenBao secret store is usable by CB-Tumblebug.
func DeleteSecret ¶
DeleteSecret deletes the secret at the given KV v2 path in OpenBao. It removes all versions and metadata for the secret.
func DeleteSshKey ¶
DeleteSshKey removes the SSH key secret from OpenBao.
func GetSshKey ¶
GetSshKey retrieves the SSH private key from OpenBao for the given namespace and SSH key ID.
func InvalidateSecretCache ¶
func InvalidateSecretCache(path string)
InvalidateSecretCache drops a cached secret (call after writes or deletes).
func IsCasConflict ¶
IsCasConflict reports whether err is a KV v2 check-and-set version conflict.
func ReadSecret ¶
ReadSecret reads a secret from OpenBao at the given path and returns the data map.
func SaveSshKey ¶
SaveSshKey stores the SSH private key in OpenBao at the namespace/sshkey path.
func WriteSecret ¶
WriteSecret writes key-value data to OpenBao at the given KV v2 path (upsert).
Types ¶
This section is empty.