Skip to content

Go: package config

Generated from the Go source by scripts/gen-docs.sh — do not edit; run it to regenerate. Canonical deep reference: pkg.go.dev/github.com/dnsid-ai/dnsid-go/config. Guides and account setup: https://docs.dnsid.ai.

import "github.com/dnsid-ai/dnsid-go/config"

Package config loads DNSid SDK configuration from sources other than code (DNSID_* environment variables and a DNSid CLI identity directory), merges partial results, and constructs an IdentityManager from them.

Loaders parse; constructors default. Each Load function returns only the fields present in its source: empty or whitespace-only values are absent, nothing is defaulted or derived, and no second source is consulted. Merge combines partial results field-wise (later wins; lists replace; LogTrust is atomic). Construct fills the dependencies the caller did not supply from LogTrust and KeySource, then calls dnsid.NewIdentityManager, which applies every default and validation.

func Construct(ctx context.Context, loaded Loaded, deps Dependencies) (*dnsid.IdentityManager, error)

Construct builds an IdentityManager from a merged Loaded and the caller’s dependencies. Caller dependencies win: LogRegistry is built from LogTrust only when deps.LogRegistry is nil, and key providers are built from KeySource only when Dnsid.Identity is present and the corresponding provider is nil. loaded.Dnsid is validated first so invalid configuration never triggers a key-file read or policy fetch; dnsid.NewIdentityManager then applies every default and validation.

func IdentityManagerFromDnsid(ctx context.Context, dir string, overlay dnsid.Config, deps Dependencies) (*dnsid.IdentityManager, error)

IdentityManagerFromDnsid is Construct(Merge(LoadCliDirectory(dir), {Dnsid: overlay}), deps). An empty dir reads ~/.dnsid.

func IdentityManagerFromEnvironment(ctx context.Context, getenv func(string) string, overlay dnsid.Config, deps Dependencies) (*dnsid.IdentityManager, error)

IdentityManagerFromEnvironment is Construct(Merge(LoadEnvironment(getenv), {Dnsid: overlay}), deps). A nil getenv reads the process environment. With no DNSID_DOMAIN the result is a verification-only manager; under `dnsid local run`, DNSID_CONFIG_DIR supplies the key files.

func RegistryClientFromEnvironment(getenv func(string) string, opts ...dnsid.RegistryClientOption) (*dnsid.HTTPRegistryClient, error)

RegistryClientFromEnvironment builds a registry client from DNSID_REGISTRY_URL and DNSID_API_KEY. A nil getenv reads the process environment. The constructor applies the loopback default when the URL is absent. Explicit opts are applied after the environment credential and win.

Dependencies are the caller-supplied runtime dependencies for Construct. Explicit fields let Construct skip loaded values displaced by the caller.

type Dependencies struct {
KeyProvider dnsid.KeyProvider
EntityKeyProvider dnsid.KeyProvider
LogRegistry *dnsidlog.LogRegistry
DNSResolver dnsid.DNSResolver
HTTPSFetcher dnsid.HTTPSFetcher
IdentityCache *dnsid.IdentityCache
HTTPClient *http.Client
}

KeySource names where local key material lives. Variants are not exclusive: CliDirectory supplies the operational key when present, otherwise KeyStorePath; EntityKeyPath supplies the entity key whenever set.

type KeySource struct {
// CliDirectory is a DNSid CLI identity directory holding private.jwk or
// <domain>/private.jwk.
CliDirectory string
// EntityKeyPath is the accountable-entity key file. LoadCliDirectory
// resolves config.json entity_key_path against the directory.
EntityKeyPath string
// KeyStorePath is a local key store file readable by dnsid.NewLocalKeyProvider.
KeyStorePath string
}

Loaded is the partial configuration produced by every source. Absent fields are their Go zero value; nil slices are absent while empty non-nil slices are present and meaningful (an explicit empty allowlist denies all).

type Loaded struct {
Dnsid dnsid.Config
LogTrust LogTrust
Registry Registry
KeySource KeySource
}

func LoadCliDirectory(dir string) (Loaded, error)

LoadCliDirectory reads <dir>/config.json written by the DNSid CLI. An empty dir reads ~/.dnsid; DNSID_CONFIG_DIR is not consulted (LoadEnvironment carries it as KeySource.CliDirectory). Persisted publication fields map into Dnsid.Identity exactly as written: status_url is never derived from server_url and no log reference is substituted. The directory becomes KeySource.CliDirectory and entity_key_path, resolved against the directory of the config.json that carries it, becomes KeySource.EntityKeyPath.

The CLI treats a root config.json as the current-identity pointer: when it names a domain and <dir>/<domain>/config.json exists, that per-identity file is read instead. A leaf identity directory is read as-is.

func LoadEnvironment(getenv func(string) string) (Loaded, error)

LoadEnvironment reads the DNSID_* variables defined by the SDK environment schema. A nil getenv reads the process environment. Values are trimmed; unset, empty, or whitespace-only variables are absent. Unknown DNSID_* variables are ignored. DNSID_DNSSEC_MODE outside auto/validated/required is an *dnsid.ArgumentError; DNSID_LOG_POLICY_FILE and DNSID_LOG_TRUST_PROFILE_FILE are read and parsed here. DNSID_API_KEY is a secret, not loaded configuration; RegistryClientFromEnvironment reads it directly without placing it in Loaded.

func Merge(base, overlay Loaded) Loaded

Merge applies overlay onto base field-wise: a present overlay field replaces the base field, an absent one leaves base unchanged. Slices replace as a whole (nil is absent, empty is present). LogTrust is replaced as a whole section when overlay sets any variant.

Scalar zero values are absent: overlays cannot clear loaded Identity strings, Verification.DNSSECMode or StatusCheckInterval, Transport.DNSServer or CABundlePath, Registry.RegistryURL, or KeySource paths. Non-nil empty slices remain present. To clear a field, edit the merged config before passing it to the ordinary constructor. No loader sets StatusCheckInterval, so its zero-value limitation affects code overlays only.

LogTrust selects the lifecycle-log trust used to build a LogRegistry when the caller does not inject one. Exactly one variant must be set when the section is present; Construct rejects two or more.

type LogTrust struct {
// Managed selects the SDK-embedded DNSid-managed trust catalog.
Managed bool
// Profile is a parsed DNSid C2SP trust-profile document.
Profile *c2sptlog.TrustProfile
// PolicyDocument is an independently trusted C2SP tlog-policy document.
PolicyDocument []byte
// PolicyURL is an independently trusted HTTPS trust-policy location.
PolicyURL string
}

Registry holds registry control-plane settings.

type Registry struct {
RegistryURL string
}

Generated by gomarkdoc