Pyrite::Providers::SystemdCreds
Inherits Pyrite::Provider < Reference < Object
Provider for Bare-Metal Fedora / RHEL / Linux servers running systemd (v250+).
Interacts with systemd's native credential management subsystem and host TPM 2.0 chips:
- High-Performance RAM Mount (
$CREDENTIALS_DIRECTORY): When launched by systemd PID 1 withSetCredentialEncrypted=bootstrap_payload:/path/to/bootstrap.enc, PID 1 unseals the secret against the host TPM 2.0 at service boot into a secure RAM disk ($CREDENTIALS_DIRECTORY/bootstrap_payload). - On-Demand TPM 2.0 Unsealing (
systemd-creds cat): If run outside a service unit, invokessystemd-creds catdirectly against the host TPM 2.0 registers.
Systemd Unit Configuration
[Service]
ExecStart=/usr/local/bin/myapp
SetCredentialEncrypted=bootstrap_payload:/etc/myapp/bootstrap.enc
Example
provider = Pyrite::Providers::SystemdCreds.new(credential_name: "bootstrap_payload")
config = Pyrite.bootstrap!(AppConfig, provider: provider)