Documentation
¶
Overview ¶
Package vault implements the Vault Transit backend used by the KMS plugin.
The Vault dependency is isolated behind the small LimitedVaultClient interface so that the authentication, token management and Transit logic can be unit tested with fakes, without a running Vault server.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type AuthClient ¶
type AuthClient interface {
// SetToken sets the token used for subsequent requests.
SetToken(token string)
// ValidateToken verifies a token without installing it on the client.
ValidateToken(ctx context.Context, token string) error
// Login authenticates using a Vault auth method and sets the resulting token.
Login(ctx context.Context, method vaultapi.AuthMethod) error
}
AuthClient is what an Authenticator needs to install and validate credentials on the shared Vault client.
type Authenticator ¶
type Authenticator interface {
// Authenticate updates the supplied client with a valid token.
Authenticate(ctx context.Context, vaultClient AuthClient) error
}
Authenticator updates a Vault client with usable credentials. Implementations re-read any credential files on every call so that rotated Kubernetes Secrets are observed without restarting the plugin.
func NewAuthenticator ¶
func NewAuthenticator(cfg *config.Config, opts ...AuthenticatorOption) (Authenticator, error)
NewAuthenticator builds the Authenticator for the configured auth method. Each auth method has its own constructor below so that adding or changing a method touches one function instead of growing this switch.
type AuthenticatorOption ¶
type AuthenticatorOption func(*authenticatorOptions)
AuthenticatorOption configures optional NewAuthenticator behavior.
type Client ¶
type Client interface {
LimitedVaultClient
Run(ctx context.Context)
}
Client is the production Vault client and its background CA reload loop.
type LimitedVaultClient ¶
type LimitedVaultClient interface {
TransitWriter
VaultTokenClient
}
LimitedVaultClient is the minimal subset of the Vault client used by this package. It is implemented for production by apiClientAdapter and by fakes in tests. It composes the narrower interfaces above so that TransitService, TokenManager and Authenticator implementations can each depend on only the methods they actually use.
type TokenLifecycleClient ¶
type TokenLifecycleClient interface {
// RenewSelf renews the current token.
RenewSelf(ctx context.Context) error
// LookupSelf returns metadata about the current token.
LookupSelf(ctx context.Context) (*vaultapi.Secret, error)
}
TokenLifecycleClient is what TokenManager calls directly to check and renew the current token, independent of how it was obtained.
type TokenManager ¶
type TokenManager struct {
// contains filtered or unexported fields
}
TokenManager owns the Vault token lifecycle. A single background loop (Run) periodically confirms the current token is still valid, renews it once its TTL runs low, and falls back to authentication when lookup rejects the token, renewal returns an auth error, or a non-renewable token is getting close to expiry. It is the only code path that ever refreshes credentials: the request path (TransitService) never triggers authentication, so a token that is valid but lacks the required policy is never "fixed" by minting a new one, and there is nothing to collapse or pace against a burst of concurrent requests, since only this single goroutine ever calls the authenticator.
func NewTokenManager ¶
func NewTokenManager(vaultClient VaultTokenClient, auth Authenticator, log logr.Logger, opts ...TokenManagerOption) *TokenManager
NewTokenManager builds a TokenManager with default tuning.
func (*TokenManager) Run ¶
func (m *TokenManager) Run(ctx context.Context)
Run is the single renew/reauth handler and the exported entry point for the manager loop: it performs an immediate check - which authenticates, since no token is set yet - and then repeats the check every checkInterval until ctx is canceled. Meant to run in a dedicated goroutine. A failed check is never fatal: the next tick tries again, so a failed initial authentication just delays the plugin becoming healthy rather than stopping it from starting.
type TokenManagerOption ¶
type TokenManagerOption func(*TokenManager)
TokenManagerOption configures optional NewTokenManager behavior.
func WithLoginTimeout ¶
func WithLoginTimeout(timeout time.Duration) TokenManagerOption
WithLoginTimeout overrides the timeout for one token check cycle, including authentication.
func WithTokenCheckInterval ¶
func WithTokenCheckInterval(interval time.Duration) TokenManagerOption
WithTokenCheckInterval overrides how often the manager checks the current token.
type TransitService ¶
type TransitService struct {
// contains filtered or unexported fields
}
TransitService is the Vault Transit backed implementation of the KMS operations. It never triggers authentication itself: it just uses whatever token TokenManager currently has set on the shared vaultClient, and maps whatever Vault returns to a gRPC error. A token that is valid but lacks the required Transit policy is not "fixed" here; it just fails until the token is replaced, since re-authenticating would produce the exact same policy.
func NewTransitService ¶
func NewTransitService(vaultClient TransitWriter, mount, key string) *TransitService
NewTransitService builds a Transit service.
func (*TransitService) Decrypt ¶
Decrypt decrypts ciphertext previously produced by Encrypt. The keyID is accepted for interface compatibility; Transit ciphertext is self describing.
func (*TransitService) Encrypt ¶
Encrypt encrypts plaintext with the Transit key and returns the ciphertext and the key ID identifying the key version used.
func (*TransitService) Status ¶
func (s *TransitService) Status(ctx context.Context) (string, error)
Status performs a live encrypt then decrypt probe against Vault and returns the current key ID. It never reports cached health: every call exercises the real backend so a broken token, policy or connection surfaces immediately.
type TransitWriter ¶
type TransitWriter interface {
// Write performs a logical write, used for Transit encrypt and decrypt.
Write(ctx context.Context, path string, data map[string]interface{}) (*vaultapi.Secret, error)
}
TransitWriter performs the logical writes used for Transit encrypt and decrypt. TransitService depends only on this, not on any auth or token lifecycle method.
type VaultTokenClient ¶
type VaultTokenClient interface {
AuthClient
TokenLifecycleClient
}
VaultTokenClient is the subset of the Vault client TokenManager depends on: AuthClient, which it hands to the configured Authenticator on every authentication attempt, plus the TokenLifecycleClient methods it calls directly to check and renew the token in between.