Documentation
¶
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func ParsePublicPEM ¶
ParsePublicPEM parses a PKIX/SPKI, certificate or PKCS #1 RSA public key PEM under AuthKit's key policy: RSA of 2048-8192 bits, P-256/384/521 or Ed25519.
Types ¶
type FileSource ¶
type FileSource struct {
// contains filtered or unexported fields
}
FileSource is the Source Watch returns: keys.json, reloaded when it changes on disk (re-rendered by Vault Agent), so a signing-key rotation needs no restart. Reads are lock-free. A malformed or unreadable file keeps the last good keys: a bad render never bricks signing (authkit #90).
func Watch ¶
func Watch(path string) (*FileSource, error)
Watch loads <path>/keys.json, the envelope {active_key_id, active_private_key_pem, public_keys: {kid: pem}}, and re-reads it every 10s when it changed. It errors when path holds no valid keys.json. Close stops the watch; reloads are logged on slog.Default.
func (*FileSource) ActiveSigner ¶
func (r *FileSource) ActiveSigner() Signer
func (*FileSource) Close ¶
func (r *FileSource) Close()
Close stops the background poller. Safe to call multiple times; optional for process-lifetime sources (primarily for tests and clean shutdown).
func (*FileSource) PublicKeys ¶
func (r *FileSource) PublicKeys() map[string]crypto.PublicKey
func (*FileSource) Reload ¶
func (r *FileSource) Reload() error
Reload re-reads keys.json, validates it, and atomically swaps it in. On any read/parse/validation failure it KEEPS the current keystore and returns the error — it never serves a partial or empty key set.
type JWK ¶
type JWK struct {
Kty string `json:"kty"`
Use string `json:"use,omitempty"`
Kid string `json:"kid,omitempty"`
Alg string `json:"alg,omitempty"`
// RSA
N string `json:"n,omitempty"`
E string `json:"e,omitempty"`
// EC / OKP
Crv string `json:"crv,omitempty"`
X string `json:"x,omitempty"`
Y string `json:"y,omitempty"`
}
JWK is a JSON Web Key (RSA, EC or OKP).
type Signer ¶
type Signer interface {
// Algorithm is the JWS alg: RS256, ES256, ES384, ES512 or EdDSA.
Algorithm() string
// KID is the key id stamped into the header and published in the JWKS.
KID() string
// Public is the verification key.
Public() crypto.PublicKey
// Sign returns the JWS signature over signingInput (the encoded header
// and payload joined by "."): PKCS #1 v1.5 for RS256, the fixed-width
// R||S pair for ES*, and the raw signature for EdDSA.
Sign(ctx context.Context, signingInput []byte) ([]byte, error)
}
Signer signs JWS signing input with one private key AuthKit never sees, so an HSM, KMS or Vault key implements it directly.
func SignerFromKey ¶
SignerFromKey wraps key, an in-process private key or any crypto.Signer (a KMS client), as a Signer. The algorithm follows the key: RSA is RS256, P-256, P-384 and P-521 are ES256, ES384 and ES512, Ed25519 is EdDSA.
type Source ¶
Source is a deployment's signing keys: the active signer, and the public keys its JWKS publishes (the active one and retired ones still verifying).
type Static ¶
type Static struct {
// Active signs.
Active Signer
// Public is every key JWKS publishes, the active one included, by kid.
Public map[string]crypto.PublicKey
}
Static is a fixed Source.
func StaticFromPEM ¶
func StaticFromPEM(activeKeyID, activePrivateKeyPEM string, publicKeysPEM map[string]string) (Static, error)
StaticFromPEM builds a Static source from the active signing key (kid and private-key PEM) plus verification-only public keys (kid to PEM, such as retired keys kept in the JWKS during rotation). It performs no I/O. An unparseable public key is an error: a verifier that silently drops a rotation key would reject every token it signed.