plugin-enc
| Placement | compiled-in (in-process) |
| Source | github.com/opencharly/plugin-enc/candy/plugin-enc |
| Version | 2026.182.0001 |
| Candy | plugin-enc |
This plugin is listed in charly/charly.yml’s compiled_plugins:, so its providers are compiled into the charly binary and register in-process.
Providers
Section titled “Providers”The reserved words this plugin serves:
enc— verb class
What it does
Section titled “What it does”ENCRYPTED-VOLUME (gocryptfs) MECHANICS plugin (C16a) — runs the gocryptfs / systemd-run –scope / fusermount3 shell mechanics that mount, unmount, initialize (auto-init on charly start), and re-key charly’s gocryptfs-backed encrypted volumes. It is the security-sensitive external-command surface carved out of charly core (the former charly/enc.go is DELETED, K-wave 2). The deploy-model around it — ResolvedBindMount / ResolveVolumeBacking (sdk/deploykit/deploy_volume.go), the config loader (LoadEncryptedVolume, sdk/deploykit/enc_probe.go), the path/probe helpers, and the credential store — is sdk/deploykit + plugin-side, and the enc shim (candy/plugin-pod/enc_cmd.go) host-prelifts a self-contained per-volume plan + resolved passphrase into this plugin’s OpExecute. Compiled-in (charly config mount/unmount/passwd + charly start call the shim, which Invokes verb:enc in-proc so the passphrase never crosses a socket).
Parameter schema
Section titled “Parameter schema”The CUE schema below is the authoritative grammar for this plugin’s input. It is the same single source that generates the plugin’s Go parameter types and answers the runtime Describe RPC, so this page cannot disagree with either.
schema/enc.cue
Section titled “schema/enc.cue”// plugin-enc's OWN self-contained CUE schema — the plugin's declaration// surface, served over Describe exactly like every other plugin's schema// (there is no schema-less plugin)://// 1. SERVE over Describe — the host splices `base ++ plugin` at the load gate// (registerPluginUnitSchema), so the plugin's declarations travel WITH it and// a self-contained schema that will not splice is a LOUD load failure.// 2. DOCUMENT — `charly docs generate` renders this plugin's page from its// providers + this schema + the candy `description:`.//// verb:enc's authored input is NOT a plugin_input: charly's in-core shim host-prelifts// the resolved encrypted-volume plan into a structured spec.EncExecInput and Invokes// OpExecute with it, so this schema DOCUMENTS the verb contract (no #*Input def).// SELF-CONTAINED: it references no base def, so it compiles STANDALONE (the property// that lets the SDK compile it serve-side).#EncPlugin: { // The capability word the plugin serves. verb: "enc"
// What the verb does, in one line (the public-docs surface): run the // gocryptfs/systemd mechanics that mount, unmount, init, and re-key charly's // gocryptfs-backed encrypted volumes. contract: string & !=""}See also the candy reference for this candy’s install surface.