Conversation
The on-chain work brings hot signing keys that control protocol funds, and a plaintext env var is not acceptable custody for them. Introduce a SecretProvider abstraction (env, SOPS-encrypted files, HashiCorp Vault KV v2 with lease renewal) behind a caching SecretStore that fails fast at startup and fails soft on refresh; wrap every value in secrecy::SecretString so it is redacted in Debug and zeroised on drop. Add HMAC key rings that sign with the current key and verify with the current or previous one for zero-downtime rotation, and a Signer abstraction with Vault Transit and AWS KMS (SigV4) backends so Stellar keys never enter process memory. Includes a rotation runbook and unit tests covering every provider/signer path against a scripted HTTP transport.
|
@Whiznificent Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
…ment-issue-120 # Conflicts: # .env.example # README.md # src/signing.rs
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #120.
What
Introduces a
SecretProviderabstraction for every secret and aSignerabstraction for Stellar ed25519 keys, so the fund-controlling hot keys never live in a container spec or in process memory.Secret retrieval
SecretProvider(async) with three real backends:EnvSecretProvider— dev/default, one env var per secret.SopsFileSecretProvider— SOPS-encrypted file, decrypted on demand via thesopsbinary (plaintext never hits disk); injectable binary path for tests.VaultSecretProvider— HashiCorp Vault KV v2, plusauth/token/renew-selflease renewal.SecretStorecaches values inArc<SecretString>: fail fast at startup (loaderrors if any secret is missing) and fail soft on refresh (refresh_loopkeeps serving the last good values and logs if the backend blips).ZENITH_SECRET_BACKEND(env/sops/vault) viaprovider_from_env().secrecy::SecretString— redacted inDebug, zeroised on drop, exposed only at the point of use.Key rotation
HmacKeyRingsigns with the current key and verifies with the current or previous key, so rotating cursors/idempotency/webhook keys has no invalid-signature window.has_previous()signals an open rotation window; dropping the previous key completes it.Remote signing
Signertrait +LocalEd25519Signer(dev/tests),VaultTransitSigner(Vault Transit ed25519), andAwsKmsSigner(AWS KMSED25519_SHA_512, requests SigV4-signed by a small in-repo implementation). The private key never enters process memory for the remote signers.Docs
docs/secrets-rotation.md— runbook for each secret class (HMAC rings, DB credentials, Stellar signing keys, Vault token)..env.examplelists the secret-related configuration.Testing
Every provider and signer path is unit-tested against a scripted HTTP transport (200/404/5xx/malformed JSON), plus: HMAC ring round-trip and rotation-window behaviour, SOPS success/failure via a stub binary, Vault KV v2 parsing and lease renewal, AWS KMS SigV4 request shape + SPKI public-key extraction, and a
SecretStringDebug-redaction test. The SigV4 implementation is validated against the canonical example from the AWS documentation.The provider trait is deliberately injected into Vault/KMS clients so a full Vault integration test (testcontainers) can be run out-of-band without making CI depend on Docker; see the runbook's Testing section.
Test evidence
fmt,clippy -D warnings, andtestpass on the branch (fork CI run).