Stores: vaultstore

Secure secrets with token-based access using github.com/dracory/vaultstore.

github.com/dracory/vaultstore

vaultstore is a secure value storage layer for Go applications. It focuses on storing encrypted secrets ("vault entries") with password-protected access and a flexible token model.


Highlights

  • Secure secret storage – values are encrypted and retrievable via tokens and optional passwords.
  • Token lifecycle – create, read, update, soft delete, or hard delete tokens using a simple API.
  • Schema via migrations – schema creation handled by migration files, not automigration.
  • Flexible queries – list secrets by token prefix, status, created range, or metadata using query interfaces.
  • Soft deletion – recoverable deletes via timestamp fields.
  • Extensible docs – repository includes detailed guides for usage, queries, and internals.

Creating a Store

func NewVaultStore(db *sql.DB, debug bool) (vaultstore.StoreInterface, error) {
    st, err := vaultstore.NewStore(vaultstore.NewStoreOptions{
        DB:                 db,
        VaultTableName:     "snv_vault_vault",
        VaultMetaTableName: "snv_vault_meta",
        PasswordMinLength:  6,
    })
    if err != nil {
        return nil, err
    }
    st.EnableDebug(debug)
    return st, nil
}
  • VaultMetaTableName specifies the table for vault metadata entries.
  • PasswordMinLength enforces a minimum password length (set to 6 in the project).
  • Debug is controlled via st.EnableDebug(debug) after store creation.
  • Schema creation is handled by migration files in database/migrations/ (invoked via migrations.MigrateAll(app)), not by automigration.

Working with Tokens

// create a token (value encrypted internally)
token, err := store.TokenCreate("secret-value", "password", 20)
if err != nil {
    log.Fatal(err)
}

// check existence
exists, _ := store.TokenExists(token)

// read
value, err := store.TokenRead(token, "password")

// update
if err := store.TokenUpdate(token, "rotated-secret", "password"); err != nil {
    log.Fatal(err)
}

// soft delete for recovery
_ = store.TokenSoftDelete(token)
  • Passwords are optional; if provided, they are required for read/update.
  • Length parameter controls generated token length.

Querying Entries

query := vaultstore.NewTokenQuery().
    SetCreatedAtGte("2025-01-01 00:00:00").
    SetWithSoftDeleted(true)

entries, err := store.TokenList(ctx, query)
count, err := store.TokenCount(ctx, query)
  • Query filters include token prefix, status, metadata, created ranges, and sort options.
  • Include soft-deleted entries for audit/recovery workflows.

  • Design Principles – review the shared store architecture across Dracory libraries.
  • Entities & Interfaces – explore the dataobject-based token model.
  • Documentation – see repository docs for usage, technical reference, and query interface details.
  • Create Your Own Store – adapt vaultstore patterns for other secure storage needs.