IInstanceSecretCrypto
Namespace: Meshmakers.Octo.Sdk.Common.Encryption
At-rest encryption primitive shared across Octo services and adapters.
Implementations are stateless with respect to the key — every call takes the key as a
Byte[] argument so the caller (typically a per-service
IOptions<T> binder) retains control over key lifecycle and rotation.
public interface IInstanceSecretCrypto
Remarks:
Wire format is byte-format-stable across implementations: the enc:v1: sentinel marks
ciphertext; the payload after the sentinel is
Base64(nonce(12) ‖ tag(16) ‖ ciphertext) using AES-256-GCM. Cross-service decrypt
round-trips work whenever both replicas hold byte-identical key values (the operational
unification path used by the OctoMesh Helm chart's global.instanceSecretKey).
Methods
Encrypt(Byte[], String)
Encrypt a UTF-8 plaintext string using the given 32-byte AES-256 key. Returns ciphertext
prefixed with the enc:v1: sentinel and Base64-wrapped.
string Encrypt(Byte[] key, string plaintext)
Parameters
key Byte[]
A 32-byte AES-256 key. The caller owns the key lifecycle.
plaintext String
The UTF-8 string to encrypt.
Returns
String
The encrypted value with the enc:v1: sentinel prefix.
Decrypt(Byte[], String)
Decrypt a value produced by IInstanceSecretCrypto.Encrypt(Byte[], String). If the value does not carry an
enc: sentinel, the value is returned unchanged — this allows mixed
plaintext/ciphertext during a gradual rollout where some rows are encrypted and others
are not yet. enc:v2:<kid>: secret envelopes are refused, never decrypted
(AB#5534); they are read through the runtime engine's secret protector. See
InstanceSecretCrypto.
string Decrypt(Byte[] key, string ciphertext)
Parameters
key Byte[]
The 32-byte AES-256 key that was used to encrypt the value.
ciphertext String
A value with the enc:v1: sentinel, or any other string.
Returns
String
The plaintext, or the original string when no sentinel is present.
IsEncrypted(String)
Returns true when the value carries the encryption sentinel prefix
(matches enc: generically so future sentinel versions are also detected). Callers
use this to gate decrypt calls without exception-driven control flow.
bool IsEncrypted(string value)
Parameters
value String
The candidate string.
Returns
Boolean
true if the string is in the encrypted wire format.