df58bc25a3
---ci--- project: orca phase: 3 milestone: v0.3 status: complete requirements: covered: [REQ-022, REQ-030, REQ-032] partial: [] ---/ci--- v0.3 milestone merged to main. Includes all v0.2 work (P08-P10) that was previously on the milestone branch but not yet merged to main, plus the v0.3 completion work (iter.Seq streaming + doctor network/db). v0.2 phases included: P08 (mTLS), P09 (scheduling), P10 (security scan). v0.3 phases: P0 (pre-execution), P1 (iter.Seq streaming), P2 (doctor), P3 (final review+ship). Total: 40 requirements, all complete. No new go.mod dependencies. Full test suite passes under -race. gofmt + go vet clean.
49 lines
1.5 KiB
Go
49 lines
1.5 KiB
Go
// Package certpaths centralizes the on-disk locations of the CA and
|
|
// server cert/key files. The CLI layer, the security layer, and the
|
|
// doctor layer all need to agree on these paths, so they're factored
|
|
// into their own package to avoid import cycles (cli <-> doctor).
|
|
package certpaths
|
|
|
|
import (
|
|
"os"
|
|
"path/filepath"
|
|
)
|
|
|
|
const (
|
|
defaultCADir = ".orca"
|
|
caCertFilename = "ca.crt"
|
|
caKeyFilename = "ca.key"
|
|
)
|
|
|
|
// Dir returns the directory the local CA lives in. Honors $ORCA_HOME
|
|
// for testability; otherwise defaults to ~/.orca.
|
|
func Dir() string {
|
|
if p := os.Getenv("ORCA_HOME"); p != "" {
|
|
return p
|
|
}
|
|
home, _ := os.UserHomeDir()
|
|
return filepath.Join(home, defaultCADir)
|
|
}
|
|
|
|
// CACertPath returns the path to ca.crt.
|
|
func CACertPath() string { return filepath.Join(Dir(), caCertFilename) }
|
|
|
|
// CAKeyPath returns the path to ca.key.
|
|
func CAKeyPath() string { return filepath.Join(Dir(), caKeyFilename) }
|
|
|
|
// ServerCertPath returns the path to server.crt.
|
|
func ServerCertPath() string { return filepath.Join(Dir(), "server.crt") }
|
|
|
|
// ServerKeyPath returns the path to server.key.
|
|
func ServerKeyPath() string { return filepath.Join(Dir(), "server.key") }
|
|
|
|
// DBPath returns the path to the orca SQLite database. Honors $ORCA_DB
|
|
// for testability and explicit override; otherwise defaults to
|
|
// ~/.orca/orca.db under the same Dir() as the cert files.
|
|
func DBPath() string {
|
|
if p := os.Getenv("ORCA_DB"); p != "" {
|
|
return p
|
|
}
|
|
return filepath.Join(Dir(), "orca.db")
|
|
}
|