using VaultSharp; namespace SwBLL.Vault; /// /// Reads secrets from HashiCorp Vault KV v2 at the "secret" mount point. Matches the /// write shape used by ClientDatabaseProvisioner.WriteSecretAsync — a single "value" key. /// public class SwVaultService : ISwVaultService { private readonly IVaultClient _vaultClient; public SwVaultService(IVaultClient vaultClient) => _vaultClient = vaultClient; public async Task GetSecretAsync(string vaultPath, CancellationToken ct) { var secret = await _vaultClient.V1.Secrets.KeyValue.V2 .ReadSecretAsync(path: vaultPath, mountPoint: "secret") .ConfigureAwait(false); return secret?.Data?.Data?["value"]?.ToString() ?? throw new InvalidOperationException($"Vault secret at path '{vaultPath}' returned empty or null data."); } }