Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

The Nine Stores

One page per store the agent speaks, each with the full pod YAML for every authentication method the store takes — copy, adjust names, apply. Everything is runnable; the consul flow is what the e2e harness runs on every pull request.

storespeaksauth methodsits page
ConsulKV over HTTPanonymous, token, kubernetes (login), jwtConsul
VaultKV v2token, kubernetes, approle, jwt, userpass, ldap, certVault
Config Serverthis project's own serverbearer tokenConfig Server
FirestoreGoogle Cloudmetadata-server (Workload Identity), access-token, emulatorFirestore
Gitany git hostanonymous, token, ssh keyGit
RedisRESPin the url (requirepass, ACL users)Redis

Common to all six:

  • The store's address rides dynamic-config.rs/endpoint — or endpoint-secret when the address itself carries a password.
  • The document's key rides dynamic-config.rs/key; the per-store syntax (mount/path, application/profile, a file path) is on the store's page.
  • Secret material rides Secrets, never annotations; the geography page has the one diagram.
  • A private CA is the same one annotation everywhere: dynamic-config.rs/ca-configmap.

Every pairing on these pages also exists as a ready-to-apply manifest in the repository's examples/ directory — twenty-three manifests plus six real-software walkthroughs, each self-contained with its Secret placeholders.

etcd, NATS, S3 — the async three

Since 0.1.1 the agent drives both of the engine's source traits: the blocking six run under a blocking task, and etcd, NATS and S3 — whose clients are async — are driven directly by the agent's own runtime. The 0.1 refusal-by-name retired with this.

The config server indirection remains the answer to a different question: a fleet of pods that should not each hold store credentials — the server holds them once.

A tenth store — GCP Secret Manager, Azure App Configuration — is a compile-time addition with a well-worn path: Adding a Store walks it end to end, worked example included, plus the two no-code compositions that cover the meantime.