Files
warmbly/internal/infrastructure/kms/provider.go
T
Matthew Meszaros a8fa4386d5 infra(kms): pluggable Provider interface + local AES-256-GCM impl
Define kms.Provider so the cipher service can swap between AWS KMS and
a self-hostable local-key path. Local impl uses AES-256-GCM with the
master key sourced from KMS_LOCAL_MASTER_KEY (base64) or KMS_LOCAL_MASTER_KEY_FILE.
Factory FromEnv selects at boot via KMS_PROVIDER; defaults to aws for
backwards compatibility.

Ciphertext blob format is opaque: switching providers requires a DEK
migration because each provider can only decrypt its own blobs.

10 tests cover round-trip, tamper detection, nil-key rejection, and
factory env-selection paths.
2026-05-27 14:40:56 +00:00

36 lines
1.2 KiB
Go

package kms
import "context"
// Provider is the abstraction over a KEK (key-encryption key) source.
//
// Implementations:
// - AWS KMS (kms.KMS — historical default)
// - Local (kms.LocalProvider — self-hostable, master key in env/file)
//
// The ciphertext blob format is opaque to the caller; only the provider that
// produced it can decrypt it. Switching providers requires a DEK migration:
// existing encrypted DEKs are unreadable to a new provider.
type Provider interface {
// GenerateDataKey returns a fresh 32-byte AES-256 plaintext DEK and a
// provider-specific ciphertext form of it (base64-encoded) suitable for
// storage in a KeyVaultStore.
GenerateDataKey(ctx context.Context) (plaintext []byte, ciphertextB64 string, err error)
// GetDecryptedKey reverses GenerateDataKey.
GetDecryptedKey(ctx context.Context, ciphertextB64 string) (plaintext []byte, err error)
// Name returns a short identifier (e.g. "aws-kms", "local") used in admin
// UI and audit logs.
Name() string
}
// Compile-time interface checks.
var (
_ Provider = (*KMS)(nil)
_ Provider = (*LocalProvider)(nil)
)
// Name satisfies Provider for the AWS implementation.
func (k *KMS) Name() string { return "aws-kms" }