encrypters

package
v0.12.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 8, 2026 License: MIT Imports: 20 Imported by: 0

Documentation

Overview

Package encrypters holds the fixed set of state encrypters a factory can use. An operator selects one by bare name in a stack encryption declaration, and the resolver looks the name up here. The Encrypter contract lives in pkg/sdk/encrypt.

Index

Constants

View Source
const (
	EnvKeyName = localencrypt.EnvKeyName
	KMSName    = "kms"
	GCPKMSName = "gcp-kms"
	NoopName   = localencrypt.NoopName
)

Key source names; Describe reports the same name the registry uses so a recorded ref resolves back to its type.

Variables

This section is empty.

Functions

func Encrypters

func Encrypters() map[string]sdkencrypt.EncrypterType

Encrypters returns the built-in state encrypters keyed by stack selector.

Types

type EnvKey

type EnvKey = local.EnvKey

func NewEnvKey

func NewEnvKey(envVar string) (*EnvKey, error)

type EnvKeyConfig

type EnvKeyConfig = localencrypt.EnvKeyConfig

EnvKeyConfig is the operator-facing body under `encryption: env-key { ... }`.

type GCPKMS added in v0.11.0

type GCPKMS struct {
	// contains filtered or unexported fields
}

func NewGCPKMS added in v0.11.0

func NewGCPKMS(client gcpKMSClient, keyID string, config map[string]any) (*GCPKMS, error)

func (*GCPKMS) Decrypt added in v0.11.0

func (k *GCPKMS) Decrypt(ciphertext []byte) ([]byte, error)

func (*GCPKMS) Describe added in v0.11.0

func (k *GCPKMS) Describe() sdkencrypt.Description

func (*GCPKMS) Encrypt added in v0.11.0

func (k *GCPKMS) Encrypt(plaintext []byte) ([]byte, error)

type GCPKMSConfig added in v0.11.0

type GCPKMSConfig struct {
	KeyID string
	GCP   *gcpcfg.Configuration
}

func (*GCPKMSConfig) Validate added in v0.11.0

func (c *GCPKMSConfig) Validate() error

type KMS

type KMS struct {
	// contains filtered or unexported fields
}

KMS seals and unseals bytes with envelope encryption through AWS KMS: payloads are sealed locally with AES-256-GCM under a 256-bit data key that KMS generates and wraps with one KMS key (named by id, ARN, or alias), and each blob stores its wrapped data key, so data keys are the only thing that crosses the wire, never the payload.

An encrypter generates one data key on first use and seals every write with it. An encrypter lives for one command, so the key's exposure is bounded by the run, GCM with random nonces stays safe for far more messages than a run writes, and readers never depend on the reuse because every blob is self-describing. Unwrapped data keys are memoized by their wrapped bytes for the same reason in the other direction: a run re-reading blobs it wrote, or several blobs sealed under one data key, costs one KMS call at most.

func NewKMS

func NewKMS(client *kms.Client, keyID string, config map[string]any) (*KMS, error)

NewKMS returns a KMS encrypter using client and the given key. config, which may be nil, is the operator's evaluated encryption block; Describe reports it so sealed files record how to decrypt.

func (*KMS) Decrypt

func (k *KMS) Decrypt(ciphertext []byte) ([]byte, error)

Decrypt opens a value produced by Encrypt. Errors on tampered or truncated bytes, and when KMS will not unwrap the stored data key.

func (*KMS) Describe added in v0.8.0

func (k *KMS) Describe() sdkencrypt.Description

Describe names the kms key source and the operator configuration that selects the key, with key-id replaced by the key ARN once the first Encrypt has resolved it.

func (*KMS) Encrypt

func (k *KMS) Encrypt(plaintext []byte) ([]byte, error)

Encrypt seals plaintext under the run's KMS data key, generating it on first use.

type KMSConfig

type KMSConfig struct {
	KeyID string
	AWS   *awscfg.Configuration
}

KMSConfig is the operator-facing body under `encryption: kms { ... }`. The aws object holds the shared AWS connection settings from pkg/awscfg.

type Noop

type Noop = local.Noop

Directories

Path Synopsis

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL