Pyrite::Provider
Abstract Base Class for all Hardware & Cloud Root-of-Trust Providers.
Providers are responsible for communicating with ambient hardware chips (TPM 2.0) or cloud cryptographic key management services (Google Cloud KMS, AWS KMS) to decrypt sealed configuration envelopes in memory.
Creating a Custom Provider
To integrate a new hardware or cloud trust anchor (e.g. HashiCorp Vault, Azure Key Vault,
Apple Secure Enclave), inherit from Pyrite::Provider and implement name and unwrap:
class VaultProvider < Pyrite::Provider
getter name : String = "HashiCorp Vault Transit"
def unwrap(envelope_path : String) : String
ciphertext = File.read(envelope_path)
# Call Vault Transit decrypt API...
decrypted_json_string
end
end
config = Pyrite.bootstrap!(AppConfig, provider: VaultProvider.new)
Instance methods
Unwraps the sealed envelope file at envelope_path and returns the decrypted
raw JSON plaintext string.
Errors
Pyrite::MissingEnvelopeError: Ifenvelope_pathdoes not exist on disk.Pyrite::HardwareAuthError: If the hardware device or cloud service rejects identity.