Files
mrcharles b43bc55963 Add backend resolver interface with file and env backends plus phase-3 stubs
Introduce the single Backend interface every credential source implements.
v0 ships two working backends: file (0600 KEY=VALUE env files, parsed in
pure Go, never sourced; looser permission masks refused before read) and
env (process-environment indirection). Bitwarden Secrets Manager and
HashiCorp Vault ship as explicit not-implemented stubs behind the same
interface so the phase-3 connectors are drop-ins. All failures are typed
ResolveErrors carrying only the ref, backend, and a fixed reason enum —
never material.

💘 Generated with Crush

Assisted-by: Crush:glm-5.2
2026-08-28 22:30:50 -05:00

23 lines
827 B
Go

package backend
import "context"
// Bitwarden is the phase-3 Bitwarden Secrets Manager backend (machine
// accounts, plain REST via stdlib — the official SDK is source-available
// and AGPL-incompatible). v0 ships the interface slot ONLY: it resolves
// nothing and returns an explicit not-implemented error naming the ref
// and backend, so the connector is a drop-in behind the same interface
// later and misconfigured rollouts fail loudly today.
type Bitwarden struct{}
// NewBitwarden returns the bitwarden stub.
func NewBitwarden() *Bitwarden { return &Bitwarden{} }
// Name implements Backend.
func (b *Bitwarden) Name() string { return "bitwarden" }
// Resolve implements Backend.
func (b *Bitwarden) Resolve(ctx context.Context, ref Ref) (string, error) {
return "", Err(ref, b.Name(), ReasonNotImplemented)
}