class

Pyrite::Provider

Inherits Reference < Object

Abstract Base Class for all Hardware & Cloud Root-of-Trust Providers.

Providers are responsible for communicating with ambient hardware chips (TPM 2.0) or cloud cryptographic key management services (Google Cloud KMS, AWS KMS) to decrypt sealed configuration envelopes in memory.

Creating a Custom Provider

To integrate a new hardware or cloud trust anchor (e.g. HashiCorp Vault, Azure Key Vault, Apple Secure Enclave), inherit from Pyrite::Provider and implement name and unwrap:

class VaultProvider < Pyrite::Provider
  getter name : String = "HashiCorp Vault Transit"

  def unwrap(envelope_path : String) : String
    ciphertext = File.read(envelope_path)
    # Call Vault Transit decrypt API...
    decrypted_json_string
  end
end

config = Pyrite.bootstrap!(AppConfig, provider: VaultProvider.new)

Instance methods

name

Returns the human-readable display name of the provider driver.

Source
unwrap(envelope_path : String) : String

Unwraps the sealed envelope file at envelope_path and returns the decrypted raw JSON plaintext string.

Errors

  • Pyrite::MissingEnvelopeError: If envelope_path does not exist on disk.
  • Pyrite::HardwareAuthError: If the hardware device or cloud service rejects identity.
Source