Feat rebrand armature (#43)
All checks were successful
CI/CD / detect-changes (push) Successful in 3s
CI/CD / test-frontend (push) Successful in 5s
CI/CD / test-go-pg (push) Successful in 2m34s
CI/CD / test-sqlite (push) Successful in 2m46s
CI/CD / build-and-deploy (push) Successful in 1m55s

Co-authored-by: Jeffrey Smith <jasafpro@gmail.com>
Co-committed-by: Jeffrey Smith <jasafpro@gmail.com>
This commit was merged in pull request #43.
This commit is contained in:
2026-03-31 23:25:37 +00:00
committed by xcaliber
parent fb5284f667
commit 680ec3b897
321 changed files with 956 additions and 1033 deletions

View File

@@ -15,7 +15,7 @@ import (
//
// Usage:
//
// switchboard vault rekey
// armature vault rekey
// ENCRYPTION_KEY = current/old key
// NEW_ENCRYPTION_KEY = new key to re-encrypt with
func Rekey(db *sql.DB, oldEnvKey, newEnvKey string) error {

View File

@@ -13,7 +13,7 @@ type VaultStatusInfo struct {
}
// VaultStatus gathers vault health metrics from the database.
// Used by both the CLI (`switchboard vault status`) and the admin API endpoint.
// Used by both the CLI (`armature vault status`) and the admin API endpoint.
func VaultStatus(db *sql.DB, encryptionKey string) (*VaultStatusInfo, error) {
if db == nil {
return nil, fmt.Errorf("database not available")

View File

@@ -1,4 +1,4 @@
// Package crypto provides API key encryption primitives for Switchboard Core.
// Package crypto provides API key encryption primitives for Armature.
//
// Two-tier model:
//
@@ -59,7 +59,7 @@ func DeriveKeyFromEnv(envValue string) ([]byte, error) {
}
// HKDF with SHA-256: extract + expand with context string for domain separation.
// No salt (nil) — the env value itself is the input keying material.
hkdfReader := hkdf.New(sha256.New, []byte(envValue), nil, []byte("switchboard-api-key-encryption-v1"))
hkdfReader := hkdf.New(sha256.New, []byte(envValue), nil, []byte("armature-api-key-encryption-v1"))
key := make([]byte, 32)
if _, err := io.ReadFull(hkdfReader, key); err != nil {
return nil, fmt.Errorf("HKDF derivation failed: %w", err)