import type { KeyWrapContext, KeyWrapper, WrappedDataKey } from './KeyWrapper'; export declare const CLOUD_KMS_WRAP_CONTEXT_PURPOSE = "xpod.ai-gateway.cloud-kms-dek-wrap"; export declare const CLOUD_KMS_WRAP_CONTEXT_VERSION = "v1"; export interface CloudKmsEncryptInput { keyArn: string; plaintext: Uint8Array; encryptionContext: Record; } export interface CloudKmsDecryptInput { keyArn?: string; ciphertext: Uint8Array; encryptionContext: Record; } export interface CloudKmsClient { encrypt(input: CloudKmsEncryptInput): Promise<{ ciphertext: Uint8Array; keyId?: string; keyVersion?: string; }>; decrypt(input: CloudKmsDecryptInput): Promise<{ plaintext: Uint8Array; keyId?: string; keyVersion?: string; }>; } export interface CloudKmsWrapperOptions { kmsClient: CloudKmsClient; keyArn: string; } /** * @deprecated Compatibility-only adapter. Production Xpod bootstrap uses the * generic Pod SecretCell keyring configured through XPOD_SECRET_CELL_*. */ export declare class CloudKmsWrapper implements KeyWrapper { private readonly kmsClient; private readonly keyArn; constructor(options: CloudKmsWrapperOptions); wrapDek(context: KeyWrapContext, dek: Uint8Array): Promise; unwrapDek(context: KeyWrapContext, wrapped: WrappedDataKey): Promise; }