Sylin.Koan.Secrets.Core
0.17.0
dotnet add package Sylin.Koan.Secrets.Core --version 0.17.0
NuGet\Install-Package Sylin.Koan.Secrets.Core -Version 0.17.0
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Sylin.Koan.Secrets.Core" Version="0.17.0" />
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Sylin.Koan.Secrets.Core" Version="0.17.0" />
<PackageReference Include="Sylin.Koan.Secrets.Core" />
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Sylin.Koan.Secrets.Core --version 0.17.0
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
#r "nuget: Sylin.Koan.Secrets.Core, 0.17.0"
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Sylin.Koan.Secrets.Core@0.17.0
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Sylin.Koan.Secrets.Core&version=0.17.0
#tool nuget:?package=Sylin.Koan.Secrets.Core&version=0.17.0
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
Koan.Secrets.Core
✅ Validated against configuration bootstrap upgrades, provider chaining, and cache expiry refresh on 2025-09-29. See
TECHNICAL.mdfor runtime architecture and edge-case coverage.
Koan’s secrets runtime coordinates provider discovery, caching, and configuration interpolation so apps can consume secret:// URIs without bespoke wiring.
Quick start
using Koan.Secrets.Abstractions;
using Koan.Secrets.Core.Configuration;
using Koan.Secrets.Core.DI;
var builder = WebApplication.CreateBuilder(args);
// Resolve ${secret://...} placeholders from configuration
builder.Configuration.AddSecretsReferenceConfiguration();
// Register the secrets runtime (env + configuration providers by default)
builder.Services
.AddKoanSecrets(options => options.DefaultTtl = TimeSpan.FromMinutes(10))
.AddProvider<VaultSecretProvider>(); // optional custom provider
var app = builder.Build();
// Upgrade bootstrap configuration providers to the DI-backed resolver once the container is ready
SecretResolvingConfigurationExtensions.UpgradeSecretsConfiguration(app.Services);
app.MapGet("/stripe-key", async (ISecretResolver resolver, CancellationToken ct) =>
{
var secret = await resolver.GetAsync(SecretId.Parse("secret://stripe/api-key"), ct);
return Results.Ok(secret.AsString());
});
app.Run();
sealed class VaultSecretProvider : ISecretProvider
{
public Task<SecretValue> GetAsync(SecretId id, CancellationToken ct) => throw new NotImplementedException();
}
AddKoanSecretswires the default env/config providers, memory cache, and resolver chain; return value lets you append custom providers.- Call
UpgradeSecretsConfigurationafter DI is fully built so configuration uses the chained resolver instead of the bootstrap fallback.
Configuration & caching guidelines
SecretsOptions.DefaultTtlcontrols how long cached material stays valid when providers omit TTL metadata.- Provide per-secret TTLs via
SecretMetadata.Ttlto align with rotation policies; the cache honours the shortest value returned. - Configuration values containing
${secret://scope/name}or wholesecret://URIs resolve automatically once the upgrade step runs. - Combine with health checks by adding a probing provider (e.g., Vault) that validates connectivity during app boot.
Operational tips
- Prefer provider-qualified URIs (
secret+vault://team/api-key) when multiple backends are active; the runtime respects theProviderhint. - Cache misses fall through each registered provider until one succeeds; order providers from fastest to slowest (config → env → remote).
- When rotating secrets, clear cached values by setting
SecretMetadata.Ttlto a low value or restarting the app; a targeted invalidation helper can be added via custom resolver wrappers. - Use structured logging (inject
ILogger<ChainSecretResolver>) to trace provider fallbacks during incident diagnosis.
Related docs
Koan.Secrets.Abstractions– identifier and payload contracts.Koan.Secrets.Connector.Vault– concrete provider leveraging Vault.docs/architecture/capability-map.md– high-level capability overview including the secrets stack.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
-
net10.0
- Microsoft.Extensions.Caching.Memory (>= 10.0.8)
- Microsoft.Extensions.Configuration (>= 10.0.8)
- Microsoft.Extensions.DependencyInjection.Abstractions (>= 10.0.8)
- Microsoft.Extensions.Hosting.Abstractions (>= 10.0.8)
- Microsoft.Extensions.Logging.Abstractions (>= 10.0.8)
- Microsoft.Extensions.Options (>= 10.0.8)
- Sylin.Koan.Core (>= 0.17.0 && < 0.18.0)
- Sylin.Koan.Secrets.Abstractions (>= 0.17.0 && < 0.18.0)
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
See release notes: https://github.com/sylin-labs/Koan-framework/releases