Skip to main content

Crate ahri_tre_secrets

Crate ahri_tre_secrets 

Source
Expand description

Canonical Secret references and Secret resolution infrastructure.

Structs§

InjectedSecretError
Safe Injected-secret failure containing no material or filesystem path.
InjectedSecretProvisionError
A path-free failure from Local foundation Secret projection setup.
InjectedSecretReference
A canonical reference to the externally projected Injected-secret tier.
InjectedSecretRequirement
One Injected reference and the exact projected version required by startup.
InjectedSecretSnapshot
Immutable set of Injected secrets resolved once during process bootstrap.
InjectedSecretVersion
An exact externally supplied version label for an Injected secret.
InjectedSecretVersionParseError
LocalManagedSecretStore
Version-1 encrypted local Managed-secret backend.
LocalProviderCredentialError
Path-free failure while creating an allow-listed Local provider credential.
LocalRootIdentityProvisionError
Path-free failure while creating Local root-identity authority.
ManagedSecretError
A disclosure-safe Managed-secret backend error.
ManagedSecretIdentity
Parsed deployment root identity. Its private key has no formatting surface.
ManagedSecretMetadata
Safe metadata returned after a Managed-secret mutation or resolution.
ManagedSecretReference
A canonical reference to the encrypted Managed-secret tier.
ManagedSecretVerification
Aggregate, disclosure-safe evidence from complete offline verification.
ManagedSecretVersion
A monotonically increasing Managed-secret version.
ResolvedInjectedSecret
One protected Injected value retained by a process-lifetime snapshot.
ResolvedManagedSecret
Protected Managed-secret material with its safe resolution metadata.
RootRotationError
A disclosure-safe root-rotation failure with aggregate phase context.
RootRotationVerification
Aggregate, disclosure-safe evidence from a staged offline root rotation.
SecretMaterial
Bounded Secret bytes protected from accidental formatting or serialization.
SecretReference
A bounded canonical logical Secret reference.
SelectedManagedSecretReader
Read-only capability that authenticates only explicitly selected Managed Secret envelopes and exposes safe metadata for them.
SourceCredentialError
SourceCredentials

Enums§

InjectedSecretErrorKind
LocalInjectedSecretReplicationError
Safe failure while an existing Local foundation capability is projected to one additional workload root during an additive deployment migration.
LocalProviderCredential
A fixed private provider artifact owned by the Local deployment foundation.
ManagedSecretErrorKind
Stable, disclosure-safe Managed-secret failure categories.
RootRotationPhase
Disclosure-safe phase of an offline root-identity rotation.
SecretMaterialError
SecretReferenceParseError
SecretTier
The storage tier named by a canonical Secret reference.

Constants§

INJECTED_SECRET_ROOT
Fixed production root for externally projected Injected secrets.
MANAGED_SECRET_ROOT
Fixed production root for the encrypted Managed-secret store.
MANAGED_SECRET_ROTATION_ROOT
Fixed production destination for an offline root-identity rotation.
MAX_SECRET_MATERIAL_BYTES
Maximum logical value size for either Secret tier.
MAX_SECRET_REFERENCE_BYTES
Maximum encoded length of a canonical Secret reference.
NEXT_ROOT_IDENTITY_PATH
Fixed production projection for the next deployment X25519 identity.
ROOT_IDENTITY_PATH
Fixed production projection for the deployment X25519 identity.

Traits§

ManagedSecretBackend
Narrow backend contract consumed by trusted bootstrap and workflows.

Functions§

generate_local_foundation_secret
Generates deployment-local bootstrap material without exposing raw Secret ownership to configuration or runtime crates.
initialize_injected_projection_for_local_foundation
Writes one new Local-deployment Injected-secret projection without exposing the projection layout to the provisioner. The caller owns the selected deployment volume; a projection is never replaced in place.
initialize_local_diagnostic_password
Generates and creates the fixed, short-lived Local database-diagnostic password export without returning its material to deployment shell code.
initialize_local_foundation_managed_store
Generates and projects a new Local root identity, then initializes the Deployment-bound Managed store without returning identity material.
initialize_local_foundation_next_root_identity
Creates the distinct next-root projection consumed only by the stopped offline rotation workload. Existing next-root state is never replaced.
initialize_local_provider_credential
Creates one allow-listed Local provider credential with protected initial permissions. Existing state is never replaced.
remove_injected_projection_for_local_acceptance
Removes one temporary Local acceptance projection without traversing or changing any sibling capability.
replace_injected_projection_for_local_acceptance
Replaces one explicitly temporary Local acceptance projection before its consuming workload starts. The reference owns a complete leaf directory; failure leaves that capability absent rather than retaining stale material.
replace_local_postgres_tls_credential_for_diagnostic
Replaces only PostgreSQL’s temporary Local diagnostic TLS credential. The broad foundation writer remains create-only; this narrower lifecycle capability exists solely for explicit diagnostic expose/revoke.
replicate_injected_projection_for_local_foundation
Replicates one immutable Local foundation projection into another workload root without returning its material to the caller. An existing valid target is retained, making the additive migration safe to rerun.