d3ade9
# /etc/custodia/custodia.conf
d3ade9
[global]
d3ade9
debug = true
d3ade9
makedirs = true
d3ade9
d3ade9
[store:sqlite]
d3ade9
handler = SqliteStore
d3ade9
dburi = ${libdir}/secrets.db
d3ade9
table = secrets
d3ade9
d3ade9
[store:encrypted_sqlite]
d3ade9
handler = EncryptedOverlay
d3ade9
backing_store = sqlite
d3ade9
master_key = ${libdir}/secrets.key
d3ade9
master_enctype = A128CBC-HS256
d3ade9
autogen_master_key = true
d3ade9
d3ade9
[auth:creds]
d3ade9
handler = SimpleCredsAuth
d3ade9
uid = root
d3ade9
gid = root
d3ade9
d3ade9
[authz:paths]
d3ade9
handler = SimplePathAuthz
d3ade9
paths = /. /secrets
d3ade9
d3ade9
[/]
d3ade9
handler = Root
d3ade9
d3ade9
[/secrets]
d3ade9
handler = Secrets
d3ade9
store = encrypted_sqlite