server

package
v0.1.0-latest-stable Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: Apache-2.0 Imports: 13 Imported by: 0

Documentation

Overview

Package server implements the Kubernetes KMS v2 gRPC service on top of a pluggable encryption Backend.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func CheckReady

func CheckReady(ctx context.Context, socketPath string) error

CheckReady connects to the KMS v2 plugin over the given Unix domain socket and verifies it reports healthy. It calls the same Status RPC the kube-apiserver uses, which performs a live backend probe, so a successful result means the running plugin can actually reach the backend and use the configured key.

It is intended for the DaemonSet readiness probe and performs no backend authentication of its own: it only talks to the local plugin socket.

func ListenUnix

func ListenUnix(socketPath string) (net.Listener, error)

ListenUnix creates the Unix domain socket listener with owner-only permissions.

func ServeListener

func ServeListener(ctx context.Context, listener net.Listener, kms kmsapi.KeyManagementServiceServer, log logr.Logger) error

ServeListener serves the KMS v2 service on an already-created listener until ctx is canceled, then gracefully stops, falling back to an immediate stop if that takes longer than gracefulStopTimeout.

Types

type Backend

type Backend interface {
	// Encrypt returns the ciphertext and the key ID used.
	Encrypt(ctx context.Context, plaintext []byte) (ciphertext []byte, keyID string, err error)
	// Decrypt returns the plaintext for the given ciphertext and key ID.
	Decrypt(ctx context.Context, ciphertext []byte, keyID string) (plaintext []byte, err error)
	// Status performs a live backend health check and returns the current key ID.
	Status(ctx context.Context) (keyID string, err error)
}

Backend performs the actual cryptographic operations. The Vault Transit service implements it; tests provide fakes.

Error contract: a returned error should already be a gRPC status error with a code the kube-apiserver can act on, e.g. Unavailable for a connectivity problem or PermissionDenied for an auth failure; see the vault package's toGRPCError for the implementation Backend uses. ensureStatusError below is only a safety net that wraps a plain error as Internal, so an implementation that skips classification degrades to an unhelpful but still valid code instead of leaking codes.Unknown to the kube-apiserver.

type Server

type Server struct {
	kmsapi.UnimplementedKeyManagementServiceServer
	// contains filtered or unexported fields
}

Server adapts a Backend to the Kubernetes KMS v2 gRPC service.

func New

func New(backend Backend, log logr.Logger) *Server

New builds a KMS v2 Server backed by the given Backend.

func (*Server) Decrypt

Decrypt decrypts the request ciphertext.

func (*Server) Encrypt

Encrypt encrypts the request plaintext.

func (*Server) Status

Status reports plugin health and the current key ID. The Backend is expected to perform a live check, so any failure is surfaced to the kube-apiserver.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL