Skip to main content

IInstanceSecretCrypto

Namespace: Meshmakers.Octo.Sdk.Common.Encryption

At-rest encryption primitive shared across Octo services and adapters. Implementations are stateless with respect to the key — every call takes the key as a Byte[] argument so the caller (typically a per-service IOptions<T> binder) retains control over key lifecycle and rotation.

public interface IInstanceSecretCrypto

Remarks:

Wire format is byte-format-stable across implementations: the enc:v1: sentinel marks ciphertext; the payload after the sentinel is Base64(nonce(12) ‖ tag(16) ‖ ciphertext) using AES-256-GCM. Cross-service decrypt round-trips work whenever both replicas hold byte-identical key values (the operational unification path used by the OctoMesh Helm chart's global.instanceSecretKey).

Methods​

Encrypt(Byte[], String)​

Encrypt a UTF-8 plaintext string using the given 32-byte AES-256 key. Returns ciphertext prefixed with the enc:v1: sentinel and Base64-wrapped.

string Encrypt(Byte[] key, string plaintext)

Parameters​

key Byte[]
A 32-byte AES-256 key. The caller owns the key lifecycle.

plaintext String
The UTF-8 string to encrypt.

Returns​

String
The encrypted value with the enc:v1: sentinel prefix.

Decrypt(Byte[], String)​

Decrypt a value produced by IInstanceSecretCrypto.Encrypt(Byte[], String). If the value does not carry an enc: sentinel, the value is returned unchanged — this allows mixed plaintext/ciphertext during a gradual rollout where some rows are encrypted and others are not yet. enc:v2:<kid>: secret envelopes are refused, never decrypted (AB#5534); they are read through the runtime engine's secret protector. See InstanceSecretCrypto.

string Decrypt(Byte[] key, string ciphertext)

Parameters​

key Byte[]
The 32-byte AES-256 key that was used to encrypt the value.

ciphertext String
A value with the enc:v1: sentinel, or any other string.

Returns​

String
The plaintext, or the original string when no sentinel is present.

IsEncrypted(String)​

Returns true when the value carries the encryption sentinel prefix (matches enc: generically so future sentinel versions are also detected). Callers use this to gate decrypt calls without exception-driven control flow.

bool IsEncrypted(string value)

Parameters​

value String
The candidate string.

Returns​

Boolean
true if the string is in the encrypted wire format.