Weave documentation
Strand Vault

Vault Lifecycle

Initialize storage, authorize a namespace, and open an agent Strand.

Initialize a known storage root

StrandVault::new(config) validates configuration, opens the configured metadata backend, loads or creates its master key, loads authorized agents and selects a persisted policy. The filesystem default is ./strand-vault, not a temporary directory. Set an explicit location for application storage.

use strand_vault::{AgentPermissions, StrandVault, VaultConfig};
use strand_vault::storage::filesystem::FileSystemStorageFactory;

async fn open_vault() -> Result<StrandVault, Box<dyn std::error::Error>> {
    let mut config = VaultConfig::default();
    config.storage_factory = Box::new(FileSystemStorageFactory::new("./example-vault"));
    let vault = StrandVault::new(config).await?;
    vault.authorize_agent("example-agent".into(), AgentPermissions::default()).await?;
    let _strand = vault.get_agent_strand("example-agent", "events").await?;
    Ok(vault)
}

This is trusted local setup. authorize_agent accepts an identifier string and permissions; its internal organization-governance validation currently returns success without external checks. Authenticate the operator before exposing it through any service.

get_agent_strand derives keys from the vault master key, namespace and name. Preserving the master key and metadata matters when reopening the same logical Strand. shutdown clears the cache and closes storage; it is not a backup operation.

Source reference

Exact declarations and source provenance · Package features and manifest.

On this page