commit 79e52850a8c8b4ef0122dce2668e6372c3aa8ed5
parent f8ab66327a7c4dc3b9f885eb3d80d7e4e26972c1
Author: triesap <tyson@radroots.org>
Date: Fri, 3 Jul 2026 06:40:07 +0000
runtime: use primary-only account secret backend
- construct account secret backend selections without fallback state
- remove the unreachable fallback-era error arm
- keep account backend resolution fail-closed for unavailable backends
- preserve the existing runtime config boundary
Diffstat:
1 file changed, 0 insertions(+), 2 deletions(-)
diff --git a/src/runtime/account.rs b/src/runtime/account.rs
@@ -765,7 +765,6 @@ fn resolve_secret_backend(
RadrootsSecretVaultError::HostVaultPolicyUnsupported { .. } => {
SecretBackendResolutionError::Invalid(format!("account secret backend: {error}"))
}
- error => SecretBackendResolutionError::Invalid(format!("account secret backend: {error}")),
})
}
@@ -802,7 +801,6 @@ fn secret_vault_for_backend(
fn account_secret_backend_selection(config: &RuntimeConfig) -> RadrootsSecretBackendSelection {
RadrootsSecretBackendSelection {
primary: config.account.secret_backend,
- fallback: None,
}
}