Secrets::MasterKey
The age master key — generated once at init, stored in
Keychain on macOS (synced across the user's Macs via iCloud
Keychain) or in a mode-0600 identity file on other platforms,
and read on demand by the rest of the shard.
Each Aloli operator has their own master key in their own
Keychain (or own home directory). recipients.toml lists the
public keys of all members of the team; vaults are encrypted
to that list (cf. v0.4.0 multi-recipients).
Storage layout, per platform
macOS → Keychain entry under (service: dev.aloli.secrets, account: master-key). The identity file at ~/.config/secrets/identity is also tolerated as a fallback if Keychain has no entry — useful when SSH'ing into a Mac without GUI session.
Linux,
FreeBSD, → Identity file at ${XDG_CONFIG_HOME:-~/.config}/ other secrets/identity, mode 0600. v0.5.0 ships this minimal
backend so a server can decrypt vaults without macOS.
Linux Secret Service / FreeBSD passphrase / Windows
Credential Manager are out of scope for v0.5 — the
file backend is the contract.
Constants
Instance methods
Generate a new master key, store it via the appropriate
backend, return the public key. Refuses if a key already exists
(use force: true to overwrite — destructive).
Replace the existing entry with a fresh value (used by
master-key import).
Read the master key from the available backend. Raises NotInitializedError if no key is present.