class

Pyrite::Providers::SystemdCreds

Inherits Pyrite::Provider < Reference < Object

Provider for Bare-Metal Fedora / RHEL / Linux servers running systemd (v250+).

Interacts with systemd's native credential management subsystem and host TPM 2.0 chips:

  1. High-Performance RAM Mount ($CREDENTIALS_DIRECTORY): When launched by systemd PID 1 with SetCredentialEncrypted=bootstrap_payload:/path/to/bootstrap.enc, PID 1 unseals the secret against the host TPM 2.0 at service boot into a secure RAM disk ($CREDENTIALS_DIRECTORY/bootstrap_payload).
  2. On-Demand TPM 2.0 Unsealing (systemd-creds cat): If run outside a service unit, invokes systemd-creds cat directly against the host TPM 2.0 registers.

Systemd Unit Configuration

[Service]
ExecStart=/usr/local/bin/myapp
SetCredentialEncrypted=bootstrap_payload:/etc/myapp/bootstrap.enc

Example

provider = Pyrite::Providers::SystemdCreds.new(credential_name: "bootstrap_payload")
config = Pyrite.bootstrap!(AppConfig, provider: provider)

Constructors

new(credential_name : String = "bootstrap_payload")

Initializes the provider with the credential name (defaults to "bootstrap_payload").

Source

Instance methods

credential_name

Credential filename inside $CREDENTIALS_DIRECTORY

Source
name

Human-readable provider name

Source
unwrap(envelope_path : String) : String

Unwraps the systemd credential from $CREDENTIALS_DIRECTORY or via systemd-creds cat.

Source