secretapi

package
v1.141.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 8, 2026 License: Apache-2.0 Imports: 7 Imported by: 0

Documentation

Overview

Package secretapi is the admin REST surface for stored secrets (#2051): list, read, create or change, and delete. The value is write-only: a PUT carries it, and no response ever does.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func Register

func Register(mux *http.ServeMux, wrap func(http.Handler) http.Handler, cfg Config)

Register mounts the secret routes, each behind wrap, the admin API's authentication.

Types

type Config

type Config struct {
	// Store holds the secrets. nil mounts nothing.
	Store Store
	// Author resolves the acting admin.
	Author func(*http.Request) string
}

Config carries the store and the parent-owned helpers.

type SecretInput

type SecretInput struct {
	Description      string   `json:"description"`
	Value            *string  `json:"value,omitempty"`
	AllowConnections []string `json:"allow_connections"`
	AllowPersonas    []string `json:"allow_personas"`
}

SecretInput is a create or a change. Value is omitted on a change that keeps the stored value.

type SecretList

type SecretList struct {
	Secrets []secretstore.Secret `json:"secrets"`
}

SecretList is the list response.

type Store

type Store interface {
	List(ctx context.Context) ([]secretstore.Secret, error)
	Get(ctx context.Context, name string) (secretstore.Secret, error)
	Put(ctx context.Context, w secretstore.Write) (secretstore.Secret, bool, error)
	Delete(ctx context.Context, name string) error
}

Store is what the routes act through. *secretstore.Store satisfies it.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL