Expand description
Canonical Secret references and Secret resolution infrastructure.
Structs§
- Injected
Secret Error - Safe Injected-secret failure containing no material or filesystem path.
- Injected
Secret Provision Error - A path-free failure from Local foundation Secret projection setup.
- Injected
Secret Reference - A canonical reference to the externally projected Injected-secret tier.
- Injected
Secret Requirement - One Injected reference and the exact projected version required by startup.
- Injected
Secret Snapshot - Immutable set of Injected secrets resolved once during process bootstrap.
- Injected
Secret Version - An exact externally supplied version label for an Injected secret.
- Injected
Secret Version Parse Error - Local
Managed Secret Store - Version-1 encrypted local Managed-secret backend.
- Local
Provider Credential Error - Path-free failure while creating an allow-listed Local provider credential.
- Local
Root Identity Provision Error - Path-free failure while creating Local root-identity authority.
- Managed
Secret Error - A disclosure-safe Managed-secret backend error.
- Managed
Secret Identity - Parsed deployment root identity. Its private key has no formatting surface.
- Managed
Secret Metadata - Safe metadata returned after a Managed-secret mutation or resolution.
- Managed
Secret Reference - A canonical reference to the encrypted Managed-secret tier.
- Managed
Secret Verification - Aggregate, disclosure-safe evidence from complete offline verification.
- Managed
Secret Version - A monotonically increasing Managed-secret version.
- Resolved
Injected Secret - One protected Injected value retained by a process-lifetime snapshot.
- Resolved
Managed Secret - Protected Managed-secret material with its safe resolution metadata.
- Root
Rotation Error - A disclosure-safe root-rotation failure with aggregate phase context.
- Root
Rotation Verification - Aggregate, disclosure-safe evidence from a staged offline root rotation.
- Secret
Material - Bounded Secret bytes protected from accidental formatting or serialization.
- Secret
Reference - A bounded canonical logical Secret reference.
- Selected
Managed Secret Reader - Read-only capability that authenticates only explicitly selected Managed Secret envelopes and exposes safe metadata for them.
- Source
Credential Error - Source
Credentials
Enums§
- Injected
Secret Error Kind - Local
Injected Secret Replication Error - Safe failure while an existing Local foundation capability is projected to one additional workload root during an additive deployment migration.
- Local
Provider Credential - A fixed private provider artifact owned by the Local deployment foundation.
- Managed
Secret Error Kind - Stable, disclosure-safe Managed-secret failure categories.
- Root
Rotation Phase - Disclosure-safe phase of an offline root-identity rotation.
- Secret
Material Error - Secret
Reference Parse Error - Secret
Tier - The storage tier named by a canonical Secret reference.
Constants§
- INJECTED_
SECRET_ ROOT - Fixed production root for externally projected Injected secrets.
- MANAGED_
SECRET_ ROOT - Fixed production root for the encrypted Managed-secret store.
- MANAGED_
SECRET_ ROTATION_ ROOT - Fixed production destination for an offline root-identity rotation.
- MAX_
SECRET_ MATERIAL_ BYTES - Maximum logical value size for either Secret tier.
- MAX_
SECRET_ REFERENCE_ BYTES - Maximum encoded length of a canonical Secret reference.
- NEXT_
ROOT_ IDENTITY_ PATH - Fixed production projection for the next deployment X25519 identity.
- ROOT_
IDENTITY_ PATH - Fixed production projection for the deployment X25519 identity.
Traits§
- Managed
Secret Backend - Narrow backend contract consumed by trusted bootstrap and workflows.
Functions§
- generate_
local_ foundation_ secret - Generates deployment-local bootstrap material without exposing raw Secret ownership to configuration or runtime crates.
- initialize_
injected_ projection_ for_ local_ foundation - Writes one new Local-deployment Injected-secret projection without exposing the projection layout to the provisioner. The caller owns the selected deployment volume; a projection is never replaced in place.
- initialize_
local_ diagnostic_ password - Generates and creates the fixed, short-lived Local database-diagnostic password export without returning its material to deployment shell code.
- initialize_
local_ foundation_ managed_ store - Generates and projects a new Local root identity, then initializes the Deployment-bound Managed store without returning identity material.
- initialize_
local_ foundation_ next_ root_ identity - Creates the distinct next-root projection consumed only by the stopped offline rotation workload. Existing next-root state is never replaced.
- initialize_
local_ provider_ credential - Creates one allow-listed Local provider credential with protected initial permissions. Existing state is never replaced.
- remove_
injected_ projection_ for_ local_ acceptance - Removes one temporary Local acceptance projection without traversing or changing any sibling capability.
- replace_
injected_ projection_ for_ local_ acceptance - Replaces one explicitly temporary Local acceptance projection before its consuming workload starts. The reference owns a complete leaf directory; failure leaves that capability absent rather than retaining stale material.
- replace_
local_ postgres_ tls_ credential_ for_ diagnostic - Replaces only PostgreSQL’s temporary Local diagnostic TLS credential. The broad foundation writer remains create-only; this narrower lifecycle capability exists solely for explicit diagnostic expose/revoke.
- replicate_
injected_ projection_ for_ local_ foundation - Replicates one immutable Local foundation projection into another workload root without returning its material to the caller. An existing valid target is retained, making the additive migration safe to rerun.