module

Secrets::Recipients

Multi-recipient roster for vault encryption.

The roster lives in ${XDG_CONFIG_HOME:-~/.config}/secrets/recipients.toml, a plain TOML file safe to commit to git (it only contains public keys). Format:

[recipients]
philippe = "age1xxx..."
alice    = "age1yyy..."
bob      = "age1zzz..."

When a vault is written out, the union of all keys in this file plus the operator's own master key is passed to age, so any listed identity can later decrypt. If the file is absent, the operator's master key alone is used (= v0.3 single-recipient behaviour, transparent for solo users).

The operator's own key is auto-included to prevent locking oneself out by typo.

Constants

RECIPIENTS_FILE = "#{Secrets::CONFIG_DIR}/recipients.toml"

Instance methods

add(name : String, key : String) : Nil

Add or update a named recipient. Validates the public key format. Persists recipients.toml (creates the file with mode 0644 on first call — public keys are not secret).

Source
encryption_keys

Public keys (in age1... form) to encrypt the next vault write against. Always includes the operator's own master key.

Source
list_named

name => age1key map of every entry in recipients.toml. Empty hash if the file is absent.

Source
remove(name : String) : Bool

Remove a named recipient. Returns true if removed, false if the name was not in the roster.

Source