Documentation
¶
Overview ¶
Package server implements the Kubernetes KMS v2 gRPC service on top of a pluggable encryption Backend.
Index ¶
- func CheckReady(ctx context.Context, socketPath string) error
- func ListenUnix(socketPath string) (net.Listener, error)
- func ServeListener(ctx context.Context, listener net.Listener, ...) error
- type Backend
- type Server
- func (s *Server) Decrypt(ctx context.Context, req *kmsapi.DecryptRequest) (*kmsapi.DecryptResponse, error)
- func (s *Server) Encrypt(ctx context.Context, req *kmsapi.EncryptRequest) (*kmsapi.EncryptResponse, error)
- func (s *Server) Status(ctx context.Context, _ *kmsapi.StatusRequest) (*kmsapi.StatusResponse, error)
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func CheckReady ¶
CheckReady connects to the KMS v2 plugin over the given Unix domain socket and verifies it reports healthy. It calls the same Status RPC the kube-apiserver uses, which performs a live backend probe, so a successful result means the running plugin can actually reach the backend and use the configured key.
It is intended for the DaemonSet readiness probe and performs no backend authentication of its own: it only talks to the local plugin socket.
func ListenUnix ¶
ListenUnix creates the Unix domain socket listener with owner-only permissions.
func ServeListener ¶
func ServeListener(ctx context.Context, listener net.Listener, kms kmsapi.KeyManagementServiceServer, log logr.Logger) error
ServeListener serves the KMS v2 service on an already-created listener until ctx is canceled, then gracefully stops, falling back to an immediate stop if that takes longer than gracefulStopTimeout.
Types ¶
type Backend ¶
type Backend interface {
// Encrypt returns the ciphertext and the key ID used.
Encrypt(ctx context.Context, plaintext []byte) (ciphertext []byte, keyID string, err error)
// Decrypt returns the plaintext for the given ciphertext and key ID.
Decrypt(ctx context.Context, ciphertext []byte, keyID string) (plaintext []byte, err error)
// Status performs a live backend health check and returns the current key ID.
Status(ctx context.Context) (keyID string, err error)
}
Backend performs the actual cryptographic operations. The Vault Transit service implements it; tests provide fakes.
Error contract: a returned error should already be a gRPC status error with a code the kube-apiserver can act on, e.g. Unavailable for a connectivity problem or PermissionDenied for an auth failure; see the vault package's toGRPCError for the implementation Backend uses. ensureStatusError below is only a safety net that wraps a plain error as Internal, so an implementation that skips classification degrades to an unhelpful but still valid code instead of leaking codes.Unknown to the kube-apiserver.
type Server ¶
type Server struct {
kmsapi.UnimplementedKeyManagementServiceServer
// contains filtered or unexported fields
}
Server adapts a Backend to the Kubernetes KMS v2 gRPC service.
func (*Server) Decrypt ¶
func (s *Server) Decrypt(ctx context.Context, req *kmsapi.DecryptRequest) (*kmsapi.DecryptResponse, error)
Decrypt decrypts the request ciphertext.
func (*Server) Encrypt ¶
func (s *Server) Encrypt(ctx context.Context, req *kmsapi.EncryptRequest) (*kmsapi.EncryptResponse, error)
Encrypt encrypts the request plaintext.
func (*Server) Status ¶
func (s *Server) Status(ctx context.Context, _ *kmsapi.StatusRequest) (*kmsapi.StatusResponse, error)
Status reports plugin health and the current key ID. The Backend is expected to perform a live check, so any failure is surfaced to the kube-apiserver.