Secrets
── Secrets ───────────────────────────────────────────────────────────────── CRUD for tenant-scoped secrets. The tenant is inferred from the request's TenantId extension (stamped by the gRPC interceptor); callers never pass it explicitly. Payloads are transmitted in plaintext over the (typically local-socket) transport; the server stores them encrypted at rest.
── Secrets ───────────────────────────────────────────────────────────────── CRUD for tenant-scoped secrets. The tenant is inferred from the request's TenantId extension (stamped by the gRPC interceptor); callers never pass it explicitly. Payloads are transmitted in plaintext over the (typically local-socket) transport; the server stores them encrypted at rest.
Service builder.Secrets, 4 rpcs.
PutSecret(PutSecretRequest) -> PutSecretResponse
Request: PutSecretRequest
message PutSecretRequest {
optional string secret_id = 1;
optional SecretPayloadProto payload = 2;
}Response: PutSecretResponse
message PutSecretResponse {
// no fields
}GetSecret(GetSecretRequest) -> GetSecretResponse
Request: GetSecretRequest
message GetSecretRequest {
optional string secret_id = 1;
}Response: GetSecretResponse
message GetSecretResponse {
optional SecretPayloadProto payload = 1;
}ListSecrets(ListSecretsRequest) -> ListSecretsResponse
Request: ListSecretsRequest
message ListSecretsRequest {
// no fields
}Response: ListSecretsResponse
message ListSecretsResponse {
repeated SecretInfoProto secrets = 1;
}DeleteSecret(DeleteSecretRequest) -> DeleteSecretResponse
Request: DeleteSecretRequest
message DeleteSecretRequest {
optional string secret_id = 1;
}Response: DeleteSecretResponse
message DeleteSecretResponse {
// no fields
}Types used above
SecretPayloadProto
Polymorphic secret payload — exactly one kind must be set.
message SecretPayloadProto {
oneof kind {
SecretKeyPayload symmetric = 1;
SecretKeyPayload public = 2;
SecretKeyPayload private = 3;
SecretMetadataPayload metadata = 4;
}
}SecretKeyPayload
A key-type secret (symmetric, public, or private).
message SecretKeyPayload {
optional string algorithm = 1;
optional string key = 2;
}| Field | |
|---|---|
algorithm | e.g. "aes-256-gcm", "ed25519", "rsa-2048" |
key | base64-encoded raw bytes or PEM string |
SecretMetadataPayload
A metadata secret: arbitrary string key/value pairs.
message SecretMetadataPayload {
optional map<string, string> data = 1;
}SecretInfoProto
Summary returned by ListSecrets (no payload, just identification metadata).
message SecretInfoProto {
optional string secret_id = 1;
optional string kind = 2;
}| Field | |
|---|---|
secret_id | |
kind | "symmetric" | "public" | "private" | "metadata" |
CidMap
── CID map ───────────────────────────────────────────────────────────────── The persistent key → CID map (docs/cid-map.md): tenant-scoped entries with TTL, pins and GC rooting, converging by newer-entry-wins. The tenant is inferred from the request's TenantId extension; callers never pass it. This service is the inspection/edit surface (UI + CLI); subsystems (sealed log streams, …) write their entries in-process.
Diagnostics
── Diagnostics ───────────────────────────────────────────────────────────── Editor tooling for bldr's own inputs (bldr-workspace.yml, build scripts), served by the daemon rather than by an IDE extension. The daemon is the only process that already knows what a workspace *means* — its members, the content each one resolves to, the build graph they produce — so an extension that re-derived any of that would be a second implementation, permanently a little behind this one. The editor therefore speaks ordinary LSP to a thin passthrough (bldr internal lsp), which does nothing but framing, and every answer comes from the node.