package crypto import ( "database/sql" "fmt" ) // VaultStatusInfo holds vault health information for admin display. type VaultStatusInfo struct { EncryptionKeySet bool `json:"encryption_key_set"` EncryptedKeys int `json:"encrypted_keys"` // provider_configs with api_key_enc VaultUsers int `json:"vault_users"` // users with vault_set = true } // VaultStatus gathers vault health metrics from the database. // Used by both the CLI (`armature vault status`) and the admin API endpoint. func VaultStatus(db *sql.DB, encryptionKey string) (*VaultStatusInfo, error) { if db == nil { return nil, fmt.Errorf("database not available") } info := &VaultStatusInfo{ EncryptionKeySet: encryptionKey != "", } // Count encrypted provider keys (global + team + personal) err := db.QueryRow(` SELECT COUNT(*) FROM provider_configs WHERE api_key_enc IS NOT NULL `).Scan(&info.EncryptedKeys) if err != nil { return nil, fmt.Errorf("count encrypted keys: %w", err) } // Count users with active vaults err = db.QueryRow(` SELECT COUNT(*) FROM users WHERE vault_set = true `).Scan(&info.VaultUsers) if err != nil { // vault_set column might not exist on very old installs info.VaultUsers = 0 } return info, nil }