Class FileSystemSecretStore
- java.lang.Object
-
- org.forgerock.secrets.propertyresolver.FileSystemSecretStore
-
- All Implemented Interfaces:
Closeable,AutoCloseable,SecretStore<Secret>
public final class FileSystemSecretStore extends Object implements SecretStore<Secret>, Closeable
ASecretStorethat reads secrets from a directory with the expectation that each file contains a separate secret. A maximum size of 2MB is imposed on files, and any file larger than this will be ignored.
-
-
Nested Class Summary
Nested Classes Modifier and Type Class Description static classFileSystemSecretStore.FileSystemSecretStoreBuilderA builder for more fluently creating a FileSystemSecretStore.
-
Field Summary
-
Fields inherited from interface org.forgerock.secrets.SecretStore
CLOCK, LEASE_EXPIRY_DURATION
-
-
Method Summary
All Methods Static Methods Instance Methods Concrete Methods Modifier and Type Method Description voidclose()static FileSystemSecretStore.FileSystemSecretStoreBuilderfileSystemSecretStoreBuilder(Path directory)Creates a new FileSystemSecretStore builder.<S extends Secret>
Promise<S,NoSuchSecretException>getActive(Purpose<S> purpose)Returns the active secret for the given purpose.<S extends Secret>
Promise<S,NoSuchSecretException>getNamed(Purpose<S> purpose, String name)Returns the named secret from this store.Class<Secret>getStoredType()The top-level class that this store is capable of storing.<S extends Secret>
Promise<Stream<S>,NeverThrowsException>getValid(Purpose<S> purpose)Returns all valid secrets for the given purpose from this store.voidrefresh()Indicates that the store should refresh its secrets from the backing storage mechanism.-
Methods inherited from class java.lang.Object
clone, equals, finalize, getClass, hashCode, notify, notifyAll, toString, wait, wait, wait
-
Methods inherited from interface org.forgerock.secrets.SecretStore
retire, revoke, rotate
-
-
-
-
Method Detail
-
fileSystemSecretStoreBuilder
public static FileSystemSecretStore.FileSystemSecretStoreBuilder fileSystemSecretStoreBuilder(Path directory)
Creates a new FileSystemSecretStore builder.- Parameters:
directory- the directory to retrieve file-based secrets from- Returns:
- a new builder
-
close
public void close()
- Specified by:
closein interfaceAutoCloseable- Specified by:
closein interfaceCloseable
-
getStoredType
public Class<Secret> getStoredType()
Description copied from interface:SecretStoreThe top-level class that this store is capable of storing. This is a reification of the type parameter and can be used to lookup stores for a given type.- Specified by:
getStoredTypein interfaceSecretStore<Secret>- Returns:
- the top-most type that this store is capable of storing, typically either
CryptoKeyfor key-stores,GenericSecretfor password stores, orSecretif the store is capable of storing any type of secret.
-
getActive
public <S extends Secret> Promise<S,NoSuchSecretException> getActive(Purpose<S> purpose)
Description copied from interface:SecretStoreReturns the active secret for the given purpose.- Specified by:
getActivein interfaceSecretStore<Secret>- Type Parameters:
S- the type of secret.- Parameters:
purpose- the purpose for which a secret is required.- Returns:
- the active secret from this store.
-
getNamed
public <S extends Secret> Promise<S,NoSuchSecretException> getNamed(Purpose<S> purpose, String name)
Description copied from interface:SecretStoreReturns the named secret from this store. The default implementation callsSecretStore.getValid(Purpose)and then returns the first valid key with a matching stable ID.- Specified by:
getNamedin interfaceSecretStore<Secret>- Type Parameters:
S- the type of secret.- Parameters:
purpose- the secret purpose.name- the name (stable id) of the secret.- Returns:
- a promise for the named secret, or a
NoSuchSecretExceptionpromise if no such secret exists.
-
getValid
public <S extends Secret> Promise<Stream<S>,NeverThrowsException> getValid(Purpose<S> purpose)
Description copied from interface:SecretStoreReturns all valid secrets for the given purpose from this store.- Specified by:
getValidin interfaceSecretStore<Secret>- Type Parameters:
S- the type of secret.- Parameters:
purpose- the purpose.- Returns:
- a stream of all valid secrets of the given type from this store, or an empty stream if none exist.
-
refresh
public void refresh()
Description copied from interface:SecretStoreIndicates that the store should refresh its secrets from the backing storage mechanism. This can be used to cause reload of a store after a secret rotation if the backend does not automatically detect such changes. Refresh may be an asynchronous operation and no guarantees are made about when clients of this secret store may see updated secrets after a call to refresh.- Specified by:
refreshin interfaceSecretStore<Secret>
-
-