Skip to content
Merged
Show file tree
Hide file tree
Changes from 2 commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
39 changes: 39 additions & 0 deletions .github/workflows/context7-refresh.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
# Context7 serves this repo's docs to coding agents, and re-indexes on its own
# schedule, which can lag a release by weeks. This asks it to re-index when a
# release is published, so agents read the docs for the version users install.
# Scope and agent rules live in context7.json.
# Endpoint: https://context7.com/docs/integrations/github-actions
name: Context7 Refresh

on:
release:
types: [published]
workflow_dispatch:

permissions: {}

jobs:
refresh:
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Ask Context7 to re-index /cachekit-io/cachekit-core
env:
CONTEXT7_API_KEY: ${{ secrets.CONTEXT7_API_KEY }}
run: |
if [ -z "$CONTEXT7_API_KEY" ]; then
echo "::error::The CONTEXT7_API_KEY secret is not available to this repository."
exit 1
fi
status=$(curl -sS --max-time 60 -o "$RUNNER_TEMP/context7-response.json" -w '%{http_code}' \
-X POST https://context7.com/api/v1/refresh \
-H "Content-Type: application/json" \
-H "Authorization: Bearer $CONTEXT7_API_KEY" \
--data '{"libraryName": "/cachekit-io/cachekit-core"}')
cat "$RUNNER_TEMP/context7-response.json"
echo
case "$status" in
202) echo "::warning::Context7 has not finalized this library yet (HTTP 202). Re-run this workflow later." ;;
2??) echo "Context7 accepted the refresh (HTTP $status)." ;;
*) echo "::error::Context7 refresh failed with HTTP $status."; exit 1 ;;
esac
4 changes: 3 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -80,7 +80,9 @@ assert_eq!(data.as_slice(), retrieved.as_slice());
use cachekit_core::{ByteStorage, ZeroKnowledgeEncryptor, derive_domain_key};

// Derive tenant-isolated key from master secret
let master_key = [0u8; 32]; // Use secure key in production!
// From your secret manager or CACHEKIT_MASTER_KEY, hex-decoded to 32 raw bytes.
// Never hard-code it, and never pass the hex string's bytes.
let master_key: [u8; 32] = load_master_key_from_secret_manager()?;
Comment thread
coderabbitai[bot] marked this conversation as resolved.
Outdated
let tenant_key = derive_domain_key(
&master_key,
"cache", // domain separation
Expand Down
20 changes: 20 additions & 0 deletions context7.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
{
"$schema": "https://context7.com/schema/context7.json",
"excludeFolders": [
".github",
"benches",
"fuzz",
"scripts",
"supply-chain",
"tests"
],
"excludeFiles": [
"CHANGELOG.md"
],
"rules": [
"Read the CacheKit master key from the CACHEKIT_MASTER_KEY environment variable or a secret manager. Never hard-code a key in source, not even a placeholder such as [0u8; 32].",
"cachekit-core reads no environment variable. Hex-decode the key (for example from `CACHEKIT_MASTER_KEY` or a secret manager) to exactly 32 raw bytes before `derive_domain_key`. Never pass the hex string's bytes: that derives a key no CacheKit SDK derives, so cross-SDK decryption fails.",
"Install the official packages: `cachekit` on PyPI, `@cachekit-io/cachekit` on npm, and `cachekit-rs` on crates.io (imported as `cachekit`). The crates.io crate named `cachekit` is an unrelated project.",
"Applications normally use a CacheKit SDK. cachekit-core is the shared byte-storage and encryption layer underneath them."
]
}
4 changes: 3 additions & 1 deletion src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,9 @@
//! use cachekit_core::{ZeroKnowledgeEncryptor, derive_domain_key};
//!
//! // Derive tenant-isolated key
//! let master_key = [0u8; 32]; // Use secure key in production!
//! // From your secret manager or CACHEKIT_MASTER_KEY, hex-decoded to 32 raw bytes.
//! // Never hard-code it, and never pass the hex string's bytes.
//! let master_key: [u8; 32] = load_master_key_from_secret_manager();
//! let tenant_key = derive_domain_key(&master_key, "cache", b"tenant-123").unwrap();
//!
//! // Encrypt
Expand Down
Loading