code wiki / vault

topic: vault

23 modules sharing the vault name family (derived from the tree's prefix discipline).

moduledescriptionlinesfuncs
nx_vault.nxsovereign secrets vault CLI (HashiCorp-Vault-class,33917
nx_vault_acl.nxsovereign path-based ACL POLICY engine (HashiCorp Vault "policies + identity" gap from402
nx_vault_acl_test.nxACLGATE: proves the path-based policy engine. Rules: secret/ -> READ;543
nx_vault_auth.nxsovereign MULTI-AUTH methods (HashiCorp Vault "auth methods" gap from302
nx_vault_auth_test.nxAUTHGATE: proves multi-auth methods end-to-end. Principals: a token, a userpass653
nx_vault_census.nxHONEST capability audit model: our sovereign Vault vs HashiCorp Vault (operator:305
nx_vault_census_test.nxVAULTCENSUSGATE: proves the HONEST Vault-vs-HashiCorp audit over the 16-feature703
nx_vault_dynamic.nxsovereign DYNAMIC SECRETS (HashiCorp Vault "dynamic secrets engines" gap from303
nx_vault_dynamic_test.nxDYNGATE: proves dynamic secrets. GREEN iff: two issues yield DISTINCT creds;513
nx_vault_gateway.nxOPAQUE-gated /vault media browser (M0 product surface) per the family-suite spec.45625
nx_vault_lease.nxsovereign LEASE / TTL / auto-expiry (HashiCorp Vault "leasing" gap from404
nx_vault_lease_test.nxLEASEGATE: proves the lease/TTL/auto-expiry engine. GREEN iff: valid within473
nx_vault_migrate.nxONE-SHOT KDF MIGRATION v1 -> v2 for every named secret in16912
nx_vault_multi.nxMULTI-SECRET vault capability (operator: "like the hashicorp vault"). Proves938
nx_vault_rotation.nxsovereign LEASE-DRIVEN AUTO-ROTATION (upgrades the rotation PARTIAL in274
nx_vault_rotation_test.nxROTATIONGATE: proves lease-driven auto-rotation. GREEN iff: not due before483
nx_vault_selftest.nxSECURITY SELF-TEST: the vault's three guarantees re-proven mechanically,977
nx_vault_shamir.nxsovereign SHAMIR threshold secret sharing (HashiCorp Vault "Shamir seal/unseal" gap607
nx_vault_shamir_test.nxSHAMIRGATE: proves K-of-N threshold unseal. Split secret into N=5 shares with745
nx_vault_suite_test.nxSUITEGATE: the workstream regression-lock for the whole sovereign Vault. Imports735
nx_vault_transit.nxsovereign TRANSIT engine (encryption-as-a-service): the HashiCorp Vault "transit"604
nx_vault_transit_test.nxTRANSITGATE: proves the sovereign transit engine (encryption-as-a-service)835
nx_vault_v3_gate.nxre-runnable GATE for the v3 vault format (Engineer verb: VERIFY).1479