module

Secrets::MasterKey

The age master key — generated once at init, stored in Keychain on macOS (synced across the user's Macs via iCloud Keychain) or in a mode-0600 identity file on other platforms, and read on demand by the rest of the shard.

Each Aloli operator has their own master key in their own Keychain (or own home directory). recipients.toml lists the public keys of all members of the team; vaults are encrypted to that list (cf. v0.4.0 multi-recipients).

Storage layout, per platform

macOS → Keychain entry under (service: dev.aloli.secrets, account: master-key). The identity file at ~/.config/secrets/identity is also tolerated as a fallback if Keychain has no entry — useful when SSH'ing into a Mac without GUI session.

Linux, FreeBSD, → Identity file at ${XDG_CONFIG_HOME:-~/.config}/ other secrets/identity, mode 0600. v0.5.0 ships this minimal backend so a server can decrypt vaults without macOS. Linux Secret Service / FreeBSD passphrase / Windows Credential Manager are out of scope for v0.5 — the file backend is the contract.

Constants

IDENTITY_FILE = "#{Secrets::CONFIG_DIR}/identity"
KEYCHAIN_ACCOUNT = "master-key"

Instance methods

exists?

True if a master key is reachable through any backend.

Source
generate!(force : Bool = false) : KeyPair

Generate a new master key, store it via the appropriate backend, return the public key. Refuses if a key already exists (use force: true to overwrite — destructive).

Source
install!(identity : String) : KeyPair

Replace the existing entry with a fresh value (used by master-key import).

Source
keygen_binary

Override the binary used for keygen (tests).

Source
read

Read the master key from the available backend. Raises NotInitializedError if no key is present.

Source

Nested types