Documentation
¶
Overview ¶
Package store provides a generic way to store credentials to connect to virtually any kind of remote system. The term `context` comes from the similar feature in Kubernetes kubectl config files.
Conceptually, a context is a set of metadata and TLS data, that can be used to connect to various endpoints of a remote system. TLS data and metadata are stored separately, so that in the future, we will be able to store sensitive information in a more secure way, depending on the os we are running on (e.g.: on Windows we could use the user Certificate Store, on macOS the user Keychain...).
Current implementation is purely file based with the following structure:
${CONTEXT_ROOT}
meta/
<context id>/meta.json: contains context medata (key/value pairs) as
well as a list of endpoints (themselves containing
key/value pair metadata).
tls/
<context id>/endpoint1/: directory containing TLS data for the endpoint1
in the corresponding context.
The context store itself has absolutely no knowledge about what a docker endpoint should contain in term of metadata or TLS config. Client code is responsible for generating and parsing endpoint metadata and TLS files. The multi-endpoints approach of this package allows to combine many different endpoints in the same "context".
Context IDs are actually SHA256 hashes of the context name, and are there only to avoid dealing with special characters in context names.
Index ¶
- func Export(name string, s Reader) io.ReadCloser
- func Import(name string, s Writer, reader io.Reader) error
- func Names(s Lister) ([]string, error)
- func ValidateContextName(name string) error
- type Config
- type ContextStore
- func (s *ContextStore) CreateOrUpdate(meta Metadata) error
- func (s *ContextStore) GetMetadata(name string) (Metadata, error)
- func (s *ContextStore) GetStorageInfo(contextName string) StorageInfo
- func (s *ContextStore) GetTLSData(contextName, endpointName, fileName string) ([]byte, error)
- func (s *ContextStore) List() ([]Metadata, error)
- func (s *ContextStore) ListTLSFiles(name string) (map[string]EndpointFiles, error)
- func (s *ContextStore) Remove(name string) error
- func (s *ContextStore) ResetEndpointTLSMaterial(contextName string, endpointName string, data *EndpointTLSData) error
- func (s *ContextStore) ResetTLSMaterial(name string, data *ContextTLSData) error
- type ContextTLSData
- type EndpointFiles
- type EndpointTLSData
- type Lister
- type Metadata
- type NamedTypeGetter
- type Reader
- type ReaderLister
- type ReaderWriter
- type StorageInfo
- type StorageInfoProvider
- type Store
- type TypeGetter
- type Writer
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func Export ¶
func Export(name string, s Reader) io.ReadCloser
Export exports an existing namespace into an opaque data stream This stream is actually a tarball containing context metadata and TLS materials, but it does not map 1:1 the layout of the context store (don't try to restore it manually without calling store.Import)