pub struct LocalManagedSecretStore { /* private fields */ }Expand description
Version-1 encrypted local Managed-secret backend.
Implementations§
Source§impl LocalManagedSecretStore
impl LocalManagedSecretStore
pub fn initialize( deployment_id: Uuid, identity: ManagedSecretIdentity, ) -> Result<Self, ManagedSecretError>
pub fn open( deployment_id: Uuid, identity: ManagedSecretIdentity, ) -> Result<Self, ManagedSecretError>
Sourcepub fn open_verified(
deployment_id: Uuid,
identity: ManagedSecretIdentity,
) -> Result<Self, ManagedSecretError>
pub fn open_verified( deployment_id: Uuid, identity: ManagedSecretIdentity, ) -> Result<Self, ManagedSecretError>
Opens a completely verified store without recovery or another mutation.
Sourcepub fn open_selected_read_only(
deployment_id: Uuid,
identity: ManagedSecretIdentity,
) -> Result<SelectedManagedSecretReader, ManagedSecretError>
pub fn open_selected_read_only( deployment_id: Uuid, identity: ManagedSecretIdentity, ) -> Result<SelectedManagedSecretReader, ManagedSecretError>
Opens the fixed store for selected, read-only resolution without recovering state or authenticating unrelated Secret envelopes.
Sourcepub fn verify_all(
deployment_id: Uuid,
identity: ManagedSecretIdentity,
) -> Result<ManagedSecretVerification, ManagedSecretError>
pub fn verify_all( deployment_id: Uuid, identity: ManagedSecretIdentity, ) -> Result<ManagedSecretVerification, ManagedSecretError>
Completely verifies the fixed active store without repair or mutation.
Sourcepub fn rotate_root(
deployment_id: Uuid,
) -> Result<RootRotationVerification, RootRotationError>
pub fn rotate_root( deployment_id: Uuid, ) -> Result<RootRotationVerification, RootRotationError>
Stages a complete root-identity rotation at the fixed production paths. The active store and both identity projections are never replaced.
Sourcepub fn list(&self) -> Result<Vec<ManagedSecretMetadata>, ManagedSecretError>
pub fn list(&self) -> Result<Vec<ManagedSecretMetadata>, ManagedSecretError>
Returns safe metadata for every active Managed secret in canonical reference order. No ciphertext or Secret material crosses this seam.
Sourcepub fn inspect(
&self,
reference: &ManagedSecretReference,
) -> Result<ManagedSecretMetadata, ManagedSecretError>
pub fn inspect( &self, reference: &ManagedSecretReference, ) -> Result<ManagedSecretMetadata, ManagedSecretError>
Authenticates one active envelope and returns only its safe metadata.
Trait Implementations§
Source§impl Debug for LocalManagedSecretStore
impl Debug for LocalManagedSecretStore
Source§impl ManagedSecretBackend for LocalManagedSecretStore
impl ManagedSecretBackend for LocalManagedSecretStore
fn create( &self, reference: &ManagedSecretReference, material: &SecretMaterial, ) -> Result<ManagedSecretMetadata, ManagedSecretError>
fn resolve( &self, reference: &ManagedSecretReference, ) -> Result<ResolvedManagedSecret, ManagedSecretError>
Source§fn lookup_active_metadata(
&self,
reference: &ManagedSecretReference,
) -> Result<ManagedSecretMetadata, ManagedSecretError>
fn lookup_active_metadata( &self, reference: &ManagedSecretReference, ) -> Result<ManagedSecretMetadata, ManagedSecretError>
Authenticates the store manifest and looks up safe active metadata
without opening the selected Secret envelope.
Auto Trait Implementations§
impl Freeze for LocalManagedSecretStore
impl !RefUnwindSafe for LocalManagedSecretStore
impl Send for LocalManagedSecretStore
impl Sync for LocalManagedSecretStore
impl Unpin for LocalManagedSecretStore
impl UnsafeUnpin for LocalManagedSecretStore
impl !UnwindSafe for LocalManagedSecretStore
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more