using System.Threading;
using System.Threading.Tasks;
namespace GB5Shared.Vault
{
///
/// Reads and writes secrets in HashiCorp Vault's KV v2 engine.
///
/// This is the only supported way for any GB5 module to touch Vault — no module should
/// hold its own IVaultClient or Vault token. Register via
/// and inject .
///
/// Example: var password = await vaultService.GetSecretAsync("gpaypass");
///
public interface IVaultService
{
///
/// Reads the secret stored at . Results are cached in-process
/// (see ) to avoid hammering Vault.
///
///
/// The secret does not exist, or the Vault operation failed after retries.
///
Task GetSecretAsync(string key, CancellationToken ct = default);
///
/// Stores at , creating or updating it.
///
///
/// The Vault operation failed after retries.
///
Task SetSecretAsync(string key, string value, CancellationToken ct = default);
}
}