Documentation
¶
Overview ¶
Package hostdelivery is the public wire contract for sealed host delivery of one secret input to the StackKit node that owns it. A delivering authority such as Techstack seals the value to a recipient key that the node generated and proved; only that node opens it into its own encrypted custody. The authority and every transport between them carry ciphertext and opaque references only.
The sealing scheme is HPKE (RFC 9180): DHKEM(X25519, HKDF-SHA256) with HKDF-SHA256 and ChaCha20-Poly1305. The canonical Context is the HPKE info, so a ciphertext opens only under the exact delivery, tenant, server, binding generation, operation, recipient key and expiry it was sealed for.
Index ¶
- Constants
- func Fingerprint(public []byte) string
- func Seal(recipientPublic []byte, context Context, plaintext []byte, now time.Time) ([]byte, error)
- func StatementDigest(payload []byte) []byte
- func VerifyStatement(statement Statement, pinnedOwnerPublic ed25519.PublicKey, challenge string, ...) error
- type Context
- type Envelope
- type Signature
- type Statement
Constants ¶
const ( EnvelopeAPIVersion = "stackkit.sealed-host-delivery/v1" StatementAPIVersion = "stackkit.host-recipient-statement/v1" // OperationBackupTargetImport delivers the owner S3 target material that // `stackkit backup target import` writes into encrypted local custody. OperationBackupTargetImport = "backup-target-import" // OperationBackupTargetRebind renews Plan authority over identical custody // when a node-issued binding has expired. OperationBackupTargetRebind = "backup-target-rebind" // MaxLifetime bounds how long one sealed delivery stays openable. MaxLifetime = 15 * time.Minute // MaxPlaintextBytes bounds the sealed material. MaxPlaintextBytes = 16 << 10 )
Variables ¶
This section is empty.
Functions ¶
func StatementDigest ¶
StatementDigest is the digest the owner key signs for a statement payload.
func VerifyStatement ¶
func VerifyStatement(statement Statement, pinnedOwnerPublic ed25519.PublicKey, challenge string, now time.Time, maxAge time.Duration) error
VerifyStatement checks the owner signature, key binding and freshness of a statement against the owner public key the caller pinned at enrollment. It proves the recipient key belongs to the holder of that owner key; it does not establish that the pinned owner key is genuine.
Types ¶
type Context ¶
type Context struct {
TenantRef string `json:"tenantRef"`
DeliveryRef string `json:"deliveryRef"`
ItemVersion uint64 `json:"itemVersion"`
SiteRef string `json:"siteRef"`
NodeRef string `json:"nodeRef"`
BindingGeneration uint64 `json:"bindingGeneration"`
Operation string `json:"operation"`
RecipientFingerprint string `json:"recipientFingerprint"`
OperationID string `json:"operationId"`
IssuedAt string `json:"issuedAt"`
NotAfter string `json:"notAfter"`
}
Context is the exact scope a delivery is sealed for. Every field is bound into the ciphertext; none is secret.
type Envelope ¶
type Envelope struct {
APIVersion string `json:"apiVersion"`
Context Context `json:"context"`
Sealed []byte `json:"sealed"`
}
Envelope is the only thing that crosses the control plane and transport.
type Signature ¶
type Signature struct {
OwnerRef string `json:"ownerRef"`
KeyID string `json:"keyId"`
Value string `json:"value"`
}
Signature is the node owner's signature over a recipient statement.
type Statement ¶
type Statement struct {
APIVersion string `json:"apiVersion"`
SiteRef string `json:"siteRef"`
NodeRef string `json:"nodeRef"`
RecipientKey string `json:"recipientKey"`
Fingerprint string `json:"fingerprint"`
Generation uint64 `json:"generation"`
Challenge string `json:"challenge"`
IssuedAt string `json:"issuedAt"`
OwnerKeyID string `json:"ownerKeyId"`
OwnerPublic string `json:"ownerPublicKey"`
Signature Signature `json:"signature"`
}
Statement is the node's proof that a recipient key belongs to it. The Challenge makes it fresh: the delivering authority supplies it and rejects a statement that does not echo it.
func (Statement) SigningBytes ¶
SigningBytes is the canonical payload the owner signs, without the signature.