secretguard

package
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: Apache-2.0 Imports: 11 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func EnabledRegistrations

func EnabledRegistrations(regs []lipsdk.Registration) ([]lipsdk.Registration, error)

EnabledRegistrations returns enabled secrets-guard feature registrations in config order.

func NewSlogObserver

func NewSlogObserver(log *slog.Logger) (sdk.Observer, error)

NewSlogObserver returns a sdk.Observer that writes secret-safe decision events to log. log must be non-nil. Finding values are never logged — only counts, the first secret ref name, and source categories.

func ValidateRegistrations

func ValidateRegistrations(regs []lipsdk.Registration) error

ValidateRegistrations validates feature registration uniqueness for secrets-guard.

Types

type Environment

type Environment = engine.Environment

Environment is the composition-injected process environment port.

type Input

type Input struct {
	AccessMode    accessmode.Mode
	Registrations []lipsdk.Registration
	RuntimeConfig *featsecretguard.RuntimeConfig
	Guards        []sdk.Guard
	Environment   Environment
	Inputs        SecretGuardInputs
	SingleUser    SingleUserOptions
	// HostInputs carries bound secret-guard host inputs when a host binding was
	// supplied (nil when absent). Explicitly-set host fields take precedence
	// over YAML-decoded catalog options.
	HostInputs       *SecretGuardInputs
	DecisionObserver sdk.Observer
	Logger           *slog.Logger
}

Input specifies explicit composition inputs for secret-guard runtime assembly. It avoids passing BuildOptions, ProcessServices, full config, or registry bags.

type MatcherOptions

type MatcherOptions = engine.MatcherOptions

MatcherOptions controls redaction presentation for the composed static matcher.

type Output

type Output struct {
	Plane     extensions.SecretGuardPlane
	Inventory *diag.InventoryExtras
}

Output carries assembled runtime extension planes and diagnostic inventory.

func Compose

func Compose(in Input) (*Output, error)

Compose assembles runtime secret-guard components from explicit typed inputs.

type SecretGuardInputs

type SecretGuardInputs struct {
	SingleUser SingleUserOptions
}

SecretGuardInputs carries single-user catalog / matcher composition overrides.

type SingleUserOptions

type SingleUserOptions = engine.SingleUserOptions

SingleUserOptions configures single-user environment catalog loading.

func ComposeSingleUser

func ComposeSingleUser(runtimeCfg featsecretguard.RuntimeConfig, inputs SingleUserOptions) SingleUserOptions

ComposeSingleUser merges YAML runtime config onto single-user options.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL