Config.Validate now parses every age_recipients entry with age.ParseX25519Recipient, so a bad recipient fails at config load instead of deep in a backup after the snapshot row and tree walk. On failure the error names the position (age_recipients[N]) and never the value: a recipient string can itself be a secret key an operator pasted by mistake, and age's own error quotes its input. An entry starting with AGE-SECRET-KEY- gets a specific message. The remaining parse sites (blobgen.NewWriter, crypto NewEncryptor and UpdateRecipients), reachable by callers that skip config.Load, likewise drop the value and age's wrapped error, naming only the position. Model: opus-4-8
28 lines
708 B
YAML
28 lines
708 B
YAML
age_recipients:
|
|
- age1278m9q7dp3chsh2dcy82qk27v047zywyvtxwnj4cvt0z65jw6a7q5dqhfj # sneak's long term age key
|
|
- age1ezrjmfpwsc95svdg0y54mums3zevgzu0x0ecq2f7tp8a05gl0sjq9q9wjg # add additional recipients as needed
|
|
snapshots:
|
|
test:
|
|
paths:
|
|
- /tmp/vaultik-test-source
|
|
- /var/test/data
|
|
exclude:
|
|
- '*.log'
|
|
- '*.tmp'
|
|
- '.git'
|
|
- 'node_modules'
|
|
s3:
|
|
endpoint: https://s3.example.com
|
|
bucket: vaultik-test-bucket
|
|
prefix: test-host/
|
|
access_key_id: test-access-key
|
|
secret_access_key: test-secret-key
|
|
region: us-east-1
|
|
use_ssl: true
|
|
part_size: 5242880 # 5MB
|
|
index_path: /tmp/vaultik-test.sqlite
|
|
chunk_size: 10MB
|
|
blob_size_limit: 10GB
|
|
compression_level: 3
|
|
hostname: test-host
|