Repository navigation
Releases: Ak-Army/config
Releases · Ak-Army/config
Release list
v1.3.0
v1.2.1
v1.2.0
v1.1.0
Adds encrypted configuration values with key rotation, a reusable generic Store[T] load target, a poll-based file watcher for backends, and hardens backend= pin resolution. This release contains a breaking change to the Load API — see below.
- New Load API. The old loader.Load(cfg) method — where you implemented a Config interface with NewSnapshot() / SetSnapshot() — is replaced by the generic free function config.Load[T](loader, store). Configuration is now loaded
into a *config.Store[T], and per-type behaviour moves into a Handler[T] (Default() / Set()).
// before
err := loader.Load(myConfigStore)
// after
store := config.NewStore[MyConfig](myHandler{})
err := config.Load(loader, store)
cfg, err := store.Config()
Features
- Encrypted configuration values with key rotation. Fields tagged encrypted can hold ENC(:) envelopes that the loader transparently decrypts. A new crypto package manages a key-ring file of named keys (one :
<base64 32-byte key> per line); values are encrypted with the active (first) key while older keys keep decrypting, so keys can be rotated without downtime. Wire it into a loader with loader.SetCrypto(...). Ships with an
AES-256-GCM implementation (crypto/aesgcm). - configcrypt CLI. A companion command to manage encrypted values:
- configcrypt -genkey — generate a fresh base64 32-byte key.
- configcrypt -key [value] — encrypt with the active key (reads from stdin when no argument is given, to keep secrets out of shell history).
- configcrypt -key -d [value] — decrypt.
- configcrypt -key -rekey [value] — re-encrypt with the active key.
- configcrypt -key -rekey -in [-write] — re-key every ENC(...) value in a config file in place, leaving all other bytes untouched.
- Generic Store[T] load target. config.NewStoreT encapsulates snapshot creation, handler-based post-processing and locked, concurrency-safe access to the loaded configuration. Store.Config() is safe to call concurrently with watcher-triggered reloads. A nil handler falls back to a zero-valued *T.
- Poll-based file watcher. backend.NewPollWatcher polls a file's mtime+size at a configurable interval and delivers fresh Content on change. Non-positive intervals fall back to a 5s default to avoid busy-looping; an empty path
yields a dormant watcher so backends with nothing to watch still return a valid Watcher. A failed read rolls the change back so it is retried on the next tick rather than silently swallowed. The file, env and consul backends
now build on it. - Encoder.DecodeValue. Encoders can now decode a raw value into a plain Go value (map[string]interface{}, []interface{} or a scalar); implemented for the JSON, YAML and TOML encoders.
Update dependencies
v1.0.1 feature: update dependencies