Skip to content

feat: convert to workspace with pluggable storage backends#2

Merged
ceejbot merged 4 commits intolatestfrom
feature/zerolease-provider
Mar 28, 2026
Merged

feat: convert to workspace with pluggable storage backends#2
ceejbot merged 4 commits intolatestfrom
feature/zerolease-provider

Conversation

@ceejbot
Copy link
Copy Markdown
Owner

@ceejbot ceejbot commented Mar 28, 2026

Split zerolease into a multi-crate workspace to support pluggable storage backends and avoid libsqlite3-sys link conflicts with downstream consumers like zeroclaw.

New crates:

  • zerolease-provider: CredentialProvider trait, ZeroleaseProvider (vault-backed), and StaticProvider (for testing/migration)
  • zerolease-store-rusqlite: RusqliteStore + RusqliteAuditLog for apps that already depend on rusqlite (e.g., zeroclaw)
  • zerolease-store-postgres: PostgresStore + PostgresAuditLog for shared infrastructure deployments (excluded from workspace due to sqlx v0.8 libsqlite3-sys conflict; builds standalone)

Core crate changes:

  • No default storage backend (consumers pick a store crate)
  • Shared serialization helpers moved to methods on CipherAlgorithm, SecretKind, and AuditEvent::indexed_fields()
  • Removed standalone bin (needs its own crate to choose a backend)
  • Updated basic_vault example to use zerolease-store-rusqlite

ceejbot added 4 commits March 28, 2026 00:56
Split zerolease into a multi-crate workspace to support pluggable
storage backends and avoid libsqlite3-sys link conflicts with
downstream consumers like zeroclaw.

New crates:
- zerolease-provider: CredentialProvider trait, ZeroleaseProvider
  (vault-backed), and StaticProvider (for testing/migration)
- zerolease-store-rusqlite: RusqliteStore + RusqliteAuditLog for
  apps that already depend on rusqlite (e.g., zeroclaw)
- zerolease-store-postgres: PostgresStore + PostgresAuditLog for
  shared infrastructure deployments (excluded from workspace due
  to sqlx v0.8 libsqlite3-sys conflict; builds standalone)

Core crate changes:
- No default storage backend (consumers pick a store crate)
- Shared serialization helpers moved to methods on CipherAlgorithm,
  SecretKind, and AuditEvent::indexed_fields()
- Removed standalone bin (needs its own crate to choose a backend)
- Updated basic_vault example to use zerolease-store-rusqlite
The test and coverage jobs referenced the removed `postgres` feature flag,
causing both to fail. Updated to use --workspace for included members and
--manifest-path for the excluded postgres crate.
It has consumers outside this crate.
…t error

Remove redundant `as Box<dyn KeySource>` cast that triggers trivial_casts
lint when the kms feature is enabled.

Use sqlx::raw_sql() instead of sqlx::query() for the audit schema
migration, since PostgreSQL's extended query protocol does not support
multiple statements in a single call.
@ceejbot ceejbot merged commit feb0eb5 into latest Mar 28, 2026
2 checks passed
@ceejbot ceejbot deleted the feature/zerolease-provider branch March 28, 2026 16:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant