Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
43 changes: 43 additions & 0 deletions .github/workflows/context7-refresh.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
# Context7 serves this repo's docs to coding agents, and re-indexes on its own
# schedule, which can lag a release by weeks. This asks it to re-index when a
# release is published, so agents read the docs for the version users install.
# Scope and agent rules live in context7.json.
# Endpoint: https://context7.com/docs/integrations/github-actions
name: Context7 Refresh

on:
release:
types: [published]
workflow_dispatch:

permissions: {}

# A release run can publish several releases at once (one per package). Queue
# them, so at most one refresh is in flight.
concurrency:
group: context7-refresh

jobs:
refresh:
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Ask Context7 to re-index /cachekit-io/cachekit-core
env:
CONTEXT7_API_KEY: ${{ secrets.CONTEXT7_API_KEY }}
run: |
if [ -z "$CONTEXT7_API_KEY" ]; then
echo "::error::The CONTEXT7_API_KEY secret is not available to this repository."
exit 1
fi
status=$(curl -sS --max-time 60 -o "$RUNNER_TEMP/context7-response.json" -w '%{http_code}' \
-X POST https://context7.com/api/v1/refresh \
-H "Content-Type: application/json" \
-H "Authorization: Bearer $CONTEXT7_API_KEY" \
--data '{"libraryName": "/cachekit-io/cachekit-core"}')
cat "$RUNNER_TEMP/context7-response.json"
echo
case "$status" in
2??) echo "Context7 accepted the refresh (HTTP $status)." ;;
*) echo "::error::Context7 refresh failed with HTTP $status."; exit 1 ;;
esac
3 changes: 2 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -80,7 +80,8 @@ assert_eq!(data.as_slice(), retrieved.as_slice());
use cachekit_core::{ByteStorage, ZeroKnowledgeEncryptor, derive_domain_key};

// Derive tenant-isolated key from master secret
let master_key = [0u8; 32]; // Use secure key in production!
// 32-byte master key from your secret manager. Never hard-code it.
let master_key: [u8; 32] = load_master_key_from_secret_manager()?;
Comment thread
coderabbitai[bot] marked this conversation as resolved.
Outdated
let tenant_key = derive_domain_key(
&master_key,
"cache", // domain separation
Expand Down
13 changes: 13 additions & 0 deletions context7.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
{
"$schema": "https://context7.com/schema/context7.json",
"folders": [],
"excludeFolders": [".github", "benches", "fuzz", "scripts", "supply-chain", "tests"],
"excludeFiles": ["CHANGELOG.md"],
"rules": [
"Read the CacheKit master key from the CACHEKIT_MASTER_KEY environment variable or a secret manager. Never hard-code a key in source, not even a placeholder such as [0u8; 32].",
"`CACHEKIT_MASTER_KEY` holds the key as a hex string. Use exactly 32 bytes (64 hex characters), for example from `openssl rand -hex 32`: it is the only length every CacheKit SDK accepts.",
"Install the official packages: `cachekit` on PyPI, `@cachekit-io/cachekit` on npm, and `cachekit-rs` on crates.io (imported as `cachekit`). The crates.io crate named `cachekit` is an unrelated project.",
"The hosted backend is CacheKit Cloud. In code it is named `CachekitIO` (in Python, `CachekitIOBackend`).",
"Applications normally use a CacheKit SDK. cachekit-core is the shared byte-storage and encryption layer underneath them."
]
}
3 changes: 2 additions & 1 deletion src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,8 @@
//! use cachekit_core::{ZeroKnowledgeEncryptor, derive_domain_key};
//!
//! // Derive tenant-isolated key
//! let master_key = [0u8; 32]; // Use secure key in production!
//! // 32-byte master key from your secret manager. Never hard-code it.
//! let master_key: [u8; 32] = load_master_key_from_secret_manager();
//! let tenant_key = derive_domain_key(&master_key, "cache", b"tenant-123").unwrap();
//!
//! // Encrypt
Expand Down
Loading