Skip to content

Add helpful string/byte wrappers for secrets and external data#188

Merged
TheJokr merged 2 commits intomainfrom
lblocher/settings-secret
Apr 9, 2026
Merged

Add helpful string/byte wrappers for secrets and external data#188
TheJokr merged 2 commits intomainfrom
lblocher/settings-secret

Conversation

@TheJokr
Copy link
Copy Markdown
Collaborator

@TheJokr TheJokr commented Apr 2, 2026

The Secret and RawSecret types help with keeping data from being leaked accidentally in a program, for example via fmt::Debug and fmt::Display. Additionally, they always zero their memory on drop. (The latter is best effort, since the underlying types can reallocate.)

MaybeExternal is an enum to load a String/Bytes/Secret/RawSecret value either inline (from the config file itself) or from an external source (environment variables or file system). This is especially useful for containerized applications, where config is routinely split between many files or injected via environment variables. The source is selected in the main config file.

Resolves #171

@TheJokr TheJokr requested a review from fisherdarling April 2, 2026 14:31
@TheJokr TheJokr self-assigned this Apr 8, 2026
Copy link
Copy Markdown
Collaborator

@fisherdarling fisherdarling left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just a small comment on perhaps not implementing Deref. Otherwise, looks good!
Can't wait to use this haha.

@TheJokr TheJokr force-pushed the lblocher/settings-secret branch from 64badf8 to 2fac784 Compare April 9, 2026 08:48
@TheJokr TheJokr merged commit eed1e9c into main Apr 9, 2026
20 checks passed
@TheJokr TheJokr deleted the lblocher/settings-secret branch April 9, 2026 09:19
TheJokr added a commit that referenced this pull request Apr 9, 2026
Added:
- The `ratelimit!` utility macro simplifies the setup required for
  rate-limiting a code block into a single macro expression. There is
  also a special `ratelimit=` prefix syntax for log statements
  specifically. (#182)
- The sentry metrics hook added in v5.5 now also supports rate-limiting
  for sentry events. To make use of this feature, call the new
  `foundations::sentry::install_hook_with_settings` setup function.
  (#183)
- The telemetry server implements a `/pprof/symbol` endpoint now, which
  can be used for remote symbolization with pprof-compatible tools.
  (#186)
- `foundations::telemetry::tracing::span_is_sampled()` provides a cheap
  way to check whether the current trace has been sampled. This allows
  skipping expensive tag/log formatting code if the values would be
  discarded anyway. (#187)
- `Secret` (string) and `RawSecret` (bytes) wrappers have been added to
  aid with confidential values in config files. Both types hide their
  contents from Debug/Display calls and require an explicit accessors to
  retrieve the secret. Additionally, they zero their memory when
  dropped. (#188)
- `MaybeExternal` is a new settings type that can load plain data
  (strings, bytes, and secrets) from either inline config or external
  sources (environment variables or file system). (#188)

Improved:
- `serde_yaml` was replaced by the new `serde-saphyr` YAML
  implementation. `serde_yaml` has been unmaintained since 2024. (#181)
- Loggers can now be frozen, meaning any further mutation (such as
  `add_fields!`) will lead to an error. This is useful to catch bugs
  where mutations are applied to the wrong logger instance. (#189)
- The maximum queue size for trace span output can now be limited via
  telemetry settings. The default has been set at 1 million spans.
  Additionally, there are new metrics to observe the queue size, total
  number of spans exported, and how many spans have been dropped. (#190)
- Tracing can now be configured with multiple concurrent output tasks to
  boost span throughput. The tasks now run independently of the
  TelemetryDriver to ensure spans are output throughout the lifetime of
  the process. (#191)

Fixed:
- Log rate limiting now correctly applies across `set_verbosity` calls.
  (#180)

Deprecated:
- `foundations::sentry::install_hook` is deprecated in favor of
  `foundations::sentry::install_hook_with_settings`.
@TheJokr TheJokr mentioned this pull request Apr 9, 2026
TheJokr added a commit that referenced this pull request Apr 9, 2026
Added:
- The `ratelimit!` utility macro simplifies the setup required for
  rate-limiting a code block into a single macro expression. There is
  also a special `ratelimit=` prefix syntax for log statements
  specifically. (#182)
- The sentry metrics hook added in v5.5 now also supports rate-limiting
  for sentry events. To make use of this feature, call the new
  `foundations::sentry::install_hook_with_settings` setup function.
  (#183)
- The telemetry server implements a `/pprof/symbol` endpoint now, which
  can be used for remote symbolization with pprof-compatible tools.
  (#186)
- `foundations::telemetry::tracing::span_is_sampled()` provides a cheap
  way to check whether the current trace has been sampled. This allows
  skipping expensive tag/log formatting code if the values would be
  discarded anyway. (#187)
- `Secret` (string) and `RawSecret` (bytes) wrappers have been added to
  aid with confidential values in config files. Both types hide their
  contents from Debug/Display calls and require an explicit accessors to
  retrieve the secret. Additionally, they zero their memory when
  dropped. (#188)
- `MaybeExternal` is a new settings type that can load plain data
  (strings, bytes, and secrets) from either inline config or external
  sources (environment variables or file system). (#188)

Improved:
- `serde_yaml` was replaced by the new `serde-saphyr` YAML
  implementation. `serde_yaml` has been unmaintained since 2024. (#181)
- Loggers can now be frozen, meaning any further mutation (such as
  `add_fields!`) will lead to an error. This is useful to catch bugs
  where mutations are applied to the wrong logger instance. (#189)
- The maximum queue size for trace span output can now be limited via
  telemetry settings. The default has been set at 1 million spans.
  Additionally, there are new metrics to observe the queue size, total
  number of spans exported, and how many spans have been dropped. (#190)
- Tracing can now be configured with multiple concurrent output tasks to
  boost span throughput. The tasks now run independently of the
  TelemetryDriver to ensure spans are output throughout the lifetime of
  the process. (#191)

Fixed:
- Log rate limiting now correctly applies across `set_verbosity` calls.
  (#180)

Deprecated:
- `foundations::sentry::install_hook` is deprecated in favor of
  `foundations::sentry::install_hook_with_settings`.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Tracking Issue for better secrets support in foundations

2 participants