vault

package
v0.1.0-latest-stable Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: Apache-2.0 Imports: 23 Imported by: 0

Documentation

Overview

Package vault implements the Vault Transit backend used by the KMS plugin.

The Vault dependency is isolated behind the small LimitedVaultClient interface so that the authentication, token management and Transit logic can be unit tested with fakes, without a running Vault server.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type AuthClient

type AuthClient interface {
	// SetToken sets the token used for subsequent requests.
	SetToken(token string)
	// ValidateToken verifies a token without installing it on the client.
	ValidateToken(ctx context.Context, token string) error
	// Login authenticates using a Vault auth method and sets the resulting token.
	Login(ctx context.Context, method vaultapi.AuthMethod) error
}

AuthClient is what an Authenticator needs to install and validate credentials on the shared Vault client.

type Authenticator

type Authenticator interface {
	// Authenticate updates the supplied client with a valid token.
	Authenticate(ctx context.Context, vaultClient AuthClient) error
}

Authenticator updates a Vault client with usable credentials. Implementations re-read any credential files on every call so that rotated Kubernetes Secrets are observed without restarting the plugin.

func NewAuthenticator

func NewAuthenticator(cfg *config.Config, opts ...AuthenticatorOption) (Authenticator, error)

NewAuthenticator builds the Authenticator for the configured auth method. Each auth method has its own constructor below so that adding or changing a method touches one function instead of growing this switch.

type AuthenticatorOption

type AuthenticatorOption func(*authenticatorOptions)

AuthenticatorOption configures optional NewAuthenticator behavior.

type Client

type Client interface {
	LimitedVaultClient
	Run(ctx context.Context)
}

Client is the production Vault client and its background CA reload loop.

func NewClient

func NewClient(address, caCertFile, namespace string, log logr.Logger) (Client, error)

NewClient builds the limited Vault client used by the KMS plugin from explicit plugin configuration.

type LimitedVaultClient

type LimitedVaultClient interface {
	TransitWriter
	VaultTokenClient
}

LimitedVaultClient is the minimal subset of the Vault client used by this package. It is implemented for production by apiClientAdapter and by fakes in tests. It composes the narrower interfaces above so that TransitService, TokenManager and Authenticator implementations can each depend on only the methods they actually use.

type TokenLifecycleClient

type TokenLifecycleClient interface {
	// RenewSelf renews the current token.
	RenewSelf(ctx context.Context) error
	// LookupSelf returns metadata about the current token.
	LookupSelf(ctx context.Context) (*vaultapi.Secret, error)
}

TokenLifecycleClient is what TokenManager calls directly to check and renew the current token, independent of how it was obtained.

type TokenManager

type TokenManager struct {
	// contains filtered or unexported fields
}

TokenManager owns the Vault token lifecycle. A single background loop (Run) periodically confirms the current token is still valid, renews it once its TTL runs low, and falls back to authentication when lookup rejects the token, renewal returns an auth error, or a non-renewable token is getting close to expiry. It is the only code path that ever refreshes credentials: the request path (TransitService) never triggers authentication, so a token that is valid but lacks the required policy is never "fixed" by minting a new one, and there is nothing to collapse or pace against a burst of concurrent requests, since only this single goroutine ever calls the authenticator.

func NewTokenManager

func NewTokenManager(vaultClient VaultTokenClient, auth Authenticator, log logr.Logger, opts ...TokenManagerOption) *TokenManager

NewTokenManager builds a TokenManager with default tuning.

func (*TokenManager) Run

func (m *TokenManager) Run(ctx context.Context)

Run is the single renew/reauth handler and the exported entry point for the manager loop: it performs an immediate check - which authenticates, since no token is set yet - and then repeats the check every checkInterval until ctx is canceled. Meant to run in a dedicated goroutine. A failed check is never fatal: the next tick tries again, so a failed initial authentication just delays the plugin becoming healthy rather than stopping it from starting.

type TokenManagerOption

type TokenManagerOption func(*TokenManager)

TokenManagerOption configures optional NewTokenManager behavior.

func WithLoginTimeout

func WithLoginTimeout(timeout time.Duration) TokenManagerOption

WithLoginTimeout overrides the timeout for one token check cycle, including authentication.

func WithTokenCheckInterval

func WithTokenCheckInterval(interval time.Duration) TokenManagerOption

WithTokenCheckInterval overrides how often the manager checks the current token.

type TransitService

type TransitService struct {
	// contains filtered or unexported fields
}

TransitService is the Vault Transit backed implementation of the KMS operations. It never triggers authentication itself: it just uses whatever token TokenManager currently has set on the shared vaultClient, and maps whatever Vault returns to a gRPC error. A token that is valid but lacks the required Transit policy is not "fixed" here; it just fails until the token is replaced, since re-authenticating would produce the exact same policy.

func NewTransitService

func NewTransitService(vaultClient TransitWriter, mount, key string) *TransitService

NewTransitService builds a Transit service.

func (*TransitService) Decrypt

func (s *TransitService) Decrypt(ctx context.Context, ciphertext []byte, _ string) ([]byte, error)

Decrypt decrypts ciphertext previously produced by Encrypt. The keyID is accepted for interface compatibility; Transit ciphertext is self describing.

func (*TransitService) Encrypt

func (s *TransitService) Encrypt(ctx context.Context, plaintext []byte) ([]byte, string, error)

Encrypt encrypts plaintext with the Transit key and returns the ciphertext and the key ID identifying the key version used.

func (*TransitService) Status

func (s *TransitService) Status(ctx context.Context) (string, error)

Status performs a live encrypt then decrypt probe against Vault and returns the current key ID. It never reports cached health: every call exercises the real backend so a broken token, policy or connection surfaces immediately.

type TransitWriter

type TransitWriter interface {
	// Write performs a logical write, used for Transit encrypt and decrypt.
	Write(ctx context.Context, path string, data map[string]interface{}) (*vaultapi.Secret, error)
}

TransitWriter performs the logical writes used for Transit encrypt and decrypt. TransitService depends only on this, not on any auth or token lifecycle method.

type VaultTokenClient

type VaultTokenClient interface {
	AuthClient
	TokenLifecycleClient
}

VaultTokenClient is the subset of the Vault client TokenManager depends on: AuthClient, which it hands to the configured Authenticator on every authentication attempt, plus the TokenLifecycleClient methods it calls directly to check and renew the token in between.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL