// Copyright Materialize, Inc. and contributors. All rights reserved.
// Use of this software is governed by the Business Source License
// included in the LICENSE file.
// As of the Change Date specified in that file, in accordance with
// the Business Source License, use of this software will be governed
// by the Apache License, Version 2.0.
//! Management of user secrets via the local file system.
use std::path::PathBuf;
use std::sync::Arc;
use anyhow::Context;
use async_trait::async_trait;
use mz_repr::CatalogItemId;
use mz_secrets::{SecretsController, SecretsReader};
use tokio::fs::{self, OpenOptions};
use tokio::io::AsyncWriteExt;
use crate::ProcessOrchestrator;
impl SecretsController for ProcessOrchestrator {
async fn ensure(&self, id: CatalogItemId, contents: &[u8]) -> Result<(), anyhow::Error> {
let file_path = self.secrets_dir.join(id.to_string());
let mut file = OpenOptions::new()
.with_context(|| format!("writing secret {id}"))?;
.with_context(|| format!("writing secret {id}"))?;
.with_context(|| format!("writing secret {id}"))?;
async fn delete(&self, id: CatalogItemId) -> Result<(), anyhow::Error> {
.with_context(|| format!("deleting secret {id}"))?;
async fn list(&self) -> Result<Vec<CatalogItemId>, anyhow::Error> {
let mut ids = Vec::new();
let mut entries = fs::read_dir(&self.secrets_dir)
.context("listing secrets")?;
while let Some(dir) = entries.next_entry().await? {
let id: CatalogItemId = dir.file_name().to_string_lossy().parse()?;
fn reader(&self) -> Arc<dyn SecretsReader> {
Arc::new(ProcessSecretsReader {
secrets_dir: self.secrets_dir.clone(),
/// A secrets reader associated with a [`ProcessOrchestrator`].
pub struct ProcessSecretsReader {
secrets_dir: PathBuf,
impl ProcessSecretsReader {
/// Constructs a new [`ProcessSecretsReader`] that reads secrets out of the
/// specified directory.
pub fn new(secrets_dir: PathBuf) -> ProcessSecretsReader {
ProcessSecretsReader { secrets_dir }
impl SecretsReader for ProcessSecretsReader {
async fn read(&self, id: CatalogItemId) -> Result<Vec<u8>, anyhow::Error> {
let contents = fs::read(self.secrets_dir.join(id.to_string()))
.with_context(|| format!("reading secret {id}"))?;