secrets

package
v0.7.3 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 21, 2026 License: MIT Imports: 7 Imported by: 0

Documentation

Overview

Package secrets provides authenticated encryption (AES-256-GCM) for secret values stored at rest — MCP HTTP headers and stdio env vars. The key comes from CHATZ_SECRETS_KEY (base64, 32 bytes). Plaintext secrets never touch the DB; only sealed blobs (nonce-prefixed ciphertext) do.

Index

Constants

View Source
const (
	// KeySize is the AES-256 key length in bytes.
	KeySize = 32
)

Variables

View Source
var (
	// ErrInvalidKey is returned when the AEAD key is not exactly KeySize bytes.
	ErrInvalidKey = errors.New("secrets: key must be 32 bytes")

	// ErrCiphertextTooShort is returned when a value to Open is shorter than
	// the nonce prefix — it can't be authentic ciphertext.
	ErrCiphertextTooShort = errors.New("secrets: ciphertext too short")

	// ErrNotConfigured is returned when a nil Box (no CHATZ_SECRETS_KEY set)
	// is asked to seal or open a non-empty secret. Boot still succeeds without
	// a key; only storing/reading a secret needs one — so a plaintext secret is
	// never written when encryption is unavailable.
	ErrNotConfigured = errors.New("secrets: no encryption key configured")
)

Secrets errors. Declared with errors.New so they stay comparable across ctxerrors.Wrap layers via errors.Is.

Functions

This section is empty.

Types

type Box

type Box struct {
	// contains filtered or unexported fields
}

Box seals and opens secret values with a single AEAD key.

func New

func New(key []byte) (*Box, error)

New builds a Box from a raw 32-byte key.

func NewFromBase64

func NewFromBase64(encoded string) (*Box, error)

NewFromBase64 builds a Box from a base64-encoded 32-byte key (the CHATZ_SECRETS_KEY form). Generate one with `openssl rand -base64 32`.

func (*Box) Open

func (b *Box) Open(sealed []byte) ([]byte, error)

Open decrypts a nonce||ciphertext blob produced by Seal. A tampered blob or wrong key fails authentication and returns an error. A nil Box (no key configured) returns ErrNotConfigured.

func (*Box) OpenMap

func (b *Box) OpenMap(sealed []byte) (map[string]string, error)

OpenMap opens a blob produced by SealMap. A nil/empty blob returns a nil map (the "no secrets" case), not an error.

func (*Box) Seal

func (b *Box) Seal(plaintext []byte) ([]byte, error)

Seal encrypts plaintext, returning nonce||ciphertext. Every call uses a fresh random nonce, so sealing the same plaintext twice yields different blobs. A nil Box (no key configured) returns ErrNotConfigured — callers must not fall back to storing plaintext.

func (*Box) SealMap

func (b *Box) SealMap(m map[string]string) ([]byte, error)

SealMap JSON-encodes a string map and seals it. An empty map returns nil so callers store NULL rather than a blob for "no secrets".

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL