Documentation
¶
Overview ¶
Per-principal CEK derivation via HKDF.
Each org/user gets a unique 256-bit Content Encryption Key derived from:
CEK = HKDF-SHA256(master_key, principal_id)
This ensures:
- Different orgs can't read each other's databases
- Master key compromise + principal ID needed to derive any CEK
- Key rotation: re-derive all CEKs from new master, re-encrypt databases
Package sqlite provides a distributed, encrypted SQLite driver for Hanzo.
Built on go-sqlite3 with sqlcipher for page-level AES-256-CBC encryption. Supports single-node, Raft consensus, CRDT sync, and threshold attestation modes.
Drop-in replacement for modernc.org/sqlite in Hanzo Base.
Threshold write attestation for multi-party SQLite.
Each party runs a node with a full replica. Write operations require t-of-n parties to sign the write before it's committed. Reads are local.
Use case: MPC wallet shard storage, DEX trade approvals, multi-sig transaction authorization in trading platforms.
Index ¶
- Variables
- func DeriveKey(masterKey []byte, principalType PrincipalType, principalID string) ([]byte, error)
- type Config
- type DB
- type Mode
- type Option
- func WithCRDT(nodeID, listen string, peers []string) Option
- func WithKey(passphrase string) Option
- func WithPeers(peers []string) Option
- func WithPrincipalKey(masterKey []byte, principalType PrincipalType, principalID string) Option
- func WithRaft(nodeID, listen string, peers []string) Option
- func WithRawKey(key []byte) Option
- func WithThreshold(t, n int, signingKey ed25519.PrivateKey) Option
- type PrincipalType
- type ThresholdManager
- func (tm *ThresholdManager) Attest(proposalID [32]byte, nodeID string, signature []byte) error
- func (tm *ThresholdManager) CleanExpired() int
- func (tm *ThresholdManager) Pending() int
- func (tm *ThresholdManager) Propose(sql string, params []any) ([32]byte, error)
- func (tm *ThresholdManager) RegisterPeer(nodeID string, pubKey ed25519.PublicKey)
- func (tm *ThresholdManager) SetCommitFunc(fn func(string, []any) error)
- type WriteProposal
Constants ¶
This section is empty.
Variables ¶
Functions ¶
func DeriveKey ¶
func DeriveKey(masterKey []byte, principalType PrincipalType, principalID string) ([]byte, error)
DeriveKey derives a 256-bit CEK for a principal from a master key using HKDF-SHA256.
masterKey: 32-byte master encryption key (from KMS) principalType: "org" or "user" principalID: unique identifier (org slug, user ID)
The info string is "{principalType}:{principalID}" ensuring domain separation.
Types ¶
type Config ¶
type Config struct {
// Encryption
RawKey []byte // raw 256-bit key (skips KDF)
// Replication
Mode Mode
NodeID string
Listen string // bind address for replication
Peers []string // peer addresses
// Threshold mode
Threshold int // t value (signatures required)
Parties int // n value (total parties)
SigningKey ed25519.PrivateKey // this node's signing key
// contains filtered or unexported fields
}
Config for opening a database.
type Option ¶
type Option func(*Config)
Option configures a database.
func WithKey ¶
WithKey derives a raw 256-bit key from a passphrase via SHA-256 and configures sqlcipher to use it directly (skipping KDF).
func WithPrincipalKey ¶
func WithPrincipalKey(masterKey []byte, principalType PrincipalType, principalID string) Option
WithPrincipalKey derives a CEK and configures the database to use it. This is the primary API for per-org and per-user encryption.
func WithRawKey ¶
WithRawKey sets a raw 256-bit encryption key (skips KDF).
func WithThreshold ¶
func WithThreshold(t, n int, signingKey ed25519.PrivateKey) Option
WithThreshold enables multi-party threshold attestation for writes.
type PrincipalType ¶
type PrincipalType string
PrincipalType identifies the type of principal for CEK derivation.
const ( PrincipalOrg PrincipalType = "org" PrincipalUser PrincipalType = "user" )
type ThresholdManager ¶
type ThresholdManager struct {
// contains filtered or unexported fields
}
ThresholdManager coordinates multi-party write attestation.
func NewThresholdManager ¶
func NewThresholdManager(threshold, parties int, nodeID string, signingKey ed25519.PrivateKey) *ThresholdManager
NewThresholdManager creates a threshold write coordinator.
func (*ThresholdManager) Attest ¶
func (tm *ThresholdManager) Attest(proposalID [32]byte, nodeID string, signature []byte) error
Attest adds a peer's attestation to a pending proposal.
func (*ThresholdManager) CleanExpired ¶
func (tm *ThresholdManager) CleanExpired() int
CleanExpired removes expired proposals.
func (*ThresholdManager) Pending ¶
func (tm *ThresholdManager) Pending() int
Pending returns the number of pending proposals.
func (*ThresholdManager) Propose ¶
func (tm *ThresholdManager) Propose(sql string, params []any) ([32]byte, error)
Propose creates a new write proposal. Returns the proposal ID.
func (*ThresholdManager) RegisterPeer ¶
func (tm *ThresholdManager) RegisterPeer(nodeID string, pubKey ed25519.PublicKey)
RegisterPeer adds a peer's public key for attestation verification.
func (*ThresholdManager) SetCommitFunc ¶
func (tm *ThresholdManager) SetCommitFunc(fn func(string, []any) error)
SetCommitFunc sets the function called when threshold is met.
type WriteProposal ¶
type WriteProposal struct {
ID [32]byte // SHA-256 of the SQL + params
SQL string
Params []any
Proposer string // node ID of proposer
CreatedAt time.Time
ExpiresAt time.Time
// contains filtered or unexported fields
}
WriteProposal is a proposed write that needs t-of-n attestations.