env

package
v1.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 8, 2026 License: AGPL-3.0 Imports: 10 Imported by: 0

Documentation

Overview

Package env reads secrets from this process's environment.

It is the secret source with nothing behind it: no network, no credentials, no vendor, no client to close. Config is empty and NewSecretSource takes no required argument. GetSecret is os.LookupEnv with the observability every other source records — the lookup key on the span, never the value.

What that buys, and what it costs

There is no failure mode between the caller and the value. A lookup cannot time out, be throttled, or fail to authenticate, and there is no per-call cost worth caching: wrapping this source in secrets.NewCachingSource adds a TTL and a refresh loop over an in-memory map read, which is work for nothing.

The cost is that rotation is invisible here. A process's environment is fixed at exec, so a secret rotated in the backing store does not reach a running process and no TTL can discover that it changed — the value this source returns on its ten-thousandth call is the value the process started with. Where key rotation must be observed without a redeploy, the gcp or ssm source under secrets.NewCachingSource is the arrangement that does it; see the secrets package's own documentation.

A variable that is not set returns secrets.ErrSecretNotFound, so a missing secret stays distinguishable from one whose value is legitimately empty.

Close logs and returns nil. There is nothing to release.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Config

type Config struct{}

Config configures the env secret source. No provider-specific fields are required.

type Option

type Option func(*options)

Option configures the secret source this package constructs. The zero configuration works: an absent logger logs nowhere, an absent tracer provider traces nowhere, and an absent metrics provider records nothing.

func WithLogger

func WithLogger(logger logging.Logger) Option

WithLogger attaches a logger.

func WithMetricsProvider

func WithMetricsProvider(metricsProvider metrics.Provider) Option

WithMetricsProvider attaches a metrics provider for the package's counters and histograms.

func WithTracerProvider

func WithTracerProvider(tracerProvider tracing.Provider) Option

WithTracerProvider attaches a tracer provider, enabling spans on every operation.

type SecretSource

type SecretSource struct {
	// contains filtered or unexported fields
}

SecretSource reads secrets from this process's environment. It is exported, and returned by NewSecretSource, so a caller can depend on this source rather than on the interface every provider shares — and so face only what this one can do, which is read a variable that is already in memory: no network, no credentials, no per-lookup cost worth caching.

func NewSecretSource

func NewSecretSource(opts ...Option) (*SecretSource, error)

NewSecretSource returns a SecretSource that reads from environment variables.

func (*SecretSource) Close

func (e *SecretSource) Close() error

func (*SecretSource) GetSecret

func (e *SecretSource) GetSecret(ctx context.Context, name string) (string, error)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL