package envelope import ( "context" "atlas9.dev/c/core" "atlas9.dev/c/core/iam" ) var ( // Cap_Dek_Create gates minting a tenant's DEK (tenant provisioning). It is a // system capability: provisioning runs before the tenant has any grants. Cap_Dek_Create = iam.NewCap("Dek_Create") // Cap_Dek_Use gates loading and unwrapping a tenant's DEK, i.e. every seal // or open on that tenant's secrets. Cap_Dek_Use = iam.NewCap("Dek_Use") ) // DEK is a data encryption key as stored: an ID and the key wrapped by the KEK. // The wrapped key is only usable after being passed through [Wrapper.Unwrap]. type DEK struct { ID core.ID WrappedKey []byte } // DekStore stores and retrieves wrapped DEKs. It performs no encryption itself; // wrapping and unwrapping are the responsibility of [EncryptorFactory]. type DekStore interface { // ForTenant returns the tenant's active DEK, or core.ErrNotFound if none exists. ForTenant(ctx context.Context, tenant core.ID) (DEK, error) // Create stores a new wrapped DEK for the tenant and returns it. Create(ctx context.Context, tenant core.ID, wrappedKey []byte) (DEK, error) }