af3cbb
# /etc/custodia/custodia.conf
af3cbb
af3cbb
[DEFAULT]
af3cbb
libdir = /var/lib/custodia
af3cbb
logdir = /var/log/custodia
af3cbb
rundir = /var/run/custodia
af3cbb
af3cbb
[global]
af3cbb
debug = true
af3cbb
server_socket = ${rundir}/custodia.sock
af3cbb
auditlog = ${logdir}/audit.log
af3cbb
af3cbb
[store:sqlite]
af3cbb
handler = SqliteStore
af3cbb
dburi = ${libdir}/secrets.db
af3cbb
table = secrets
af3cbb
af3cbb
[store:encrypted_sqlite]
af3cbb
handler = EncryptedOverlay
af3cbb
backing_store = sqlite
af3cbb
master_key = ${libdir}/secrets.key
af3cbb
master_enctype = A128CBC-HS256
af3cbb
autogen_master_key = true
af3cbb
af3cbb
[auth:creds]
af3cbb
handler = SimpleCredsAuth
af3cbb
uid = root
af3cbb
gid = root
af3cbb
af3cbb
[authz:paths]
af3cbb
handler = SimplePathAuthz
af3cbb
paths = /. /secrets
af3cbb
af3cbb
[/]
af3cbb
handler = Root
af3cbb
af3cbb
[/secrets]
af3cbb
handler = Secrets
af3cbb
store = encrypted_sqlite