secret

package
v0.13.5 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 8, 2026 License: Apache-2.0 Imports: 8 Imported by: 0

Documentation

Overview

Package secret provides unified access to secret storage (OpenBao / HashiCorp Vault).

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func BuildSshKeySecretPath

func BuildSshKeySecretPath(nsId, sshKeyId string) string

BuildSshKeySecretPath builds the OpenBao secret path for a given SSH key.

func CheckStatus

func CheckStatus(ctx context.Context) model.OpenBaoStatusInfo

CheckStatus verifies that the OpenBao secret store is usable by CB-Tumblebug.

func DeleteSecret

func DeleteSecret(ctx context.Context, path string) error

DeleteSecret deletes the secret at the given KV v2 path in OpenBao. It removes all versions and metadata for the secret.

func DeleteSshKey

func DeleteSshKey(ctx context.Context, nsId, sshKeyId string) error

DeleteSshKey removes the SSH key secret from OpenBao.

func GetSshKey

func GetSshKey(ctx context.Context, nsId, sshKeyId string) (string, error)

GetSshKey retrieves the SSH private key from OpenBao for the given namespace and SSH key ID.

func InvalidateSecretCache

func InvalidateSecretCache(path string)

InvalidateSecretCache drops a cached secret (call after writes or deletes).

func IsCasConflict

func IsCasConflict(err error) bool

IsCasConflict reports whether err is a KV v2 check-and-set version conflict.

func ReadSecret

func ReadSecret(ctx context.Context, path string) (map[string]any, error)

ReadSecret reads a secret from OpenBao at the given path and returns the data map.

func SaveSshKey

func SaveSshKey(ctx context.Context, nsId, sshKeyId, privateKey string) error

SaveSshKey stores the SSH private key in OpenBao at the namespace/sshkey path.

func WriteSecret

func WriteSecret(ctx context.Context, path string, data map[string]any) error

WriteSecret writes key-value data to OpenBao at the given KV v2 path (upsert).

func WriteSecretIfAbsent

func WriteSecretIfAbsent(ctx context.Context, path string, data map[string]any) (created bool, err error)

WriteSecretIfAbsent writes key-value data to OpenBao only when no version of the secret exists yet (KV v2 check-and-set with cas=0).

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL