Documentation
¶
Overview ¶
Package remote resolves secret references over RPC, for nodes that hold no key material.
A distributed runner can reach the entity store but not the cluster keyring, so it cannot decrypt a stored secret itself. It asks the coordinator instead: the bytes are decrypted where the keyring lives and travel back over the authenticated RPC connection the runner already holds, to be held in memory only for as long as it takes to hand them to a container.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Resolver ¶
type Resolver struct {
// contains filtered or unexported fields
}
Resolver resolves references through the coordinator's secrets service.
func NewResolver ¶
func NewResolver(client *secret_v1alpha.SecretsClient) *Resolver
NewResolver wraps a secrets client as a Resolver.
func (*Resolver) ResolveRef ¶
ResolveRef fetches a reference's value from the coordinator.
The error deliberately names the backend and reference but not the upstream error's full text, which could quote surrounding context back into a log on a node that has no business holding it.