import { VaultKeystore } from "./vault-keystore.js"; import type { VaultMirrorCredential, VaultMirrorDestination } from "./vault-mirror-config.js"; /** `byo/.json` — where THIS machine writes a BYO vault's payload objects, and which credential NAME resolves it at use time. */ export interface VaultByoConfig { version: 1; repo_id: string; destination: VaultMirrorDestination; /** Present only for an `s3` destination — a directory destination needs no credential. */ credential?: VaultMirrorCredential; created_at: string; updated_at: string; } export declare function byoConfigDir(keystore: VaultKeystore): string; export declare function byoConfigPath(keystore: VaultKeystore, repoId: string): string; /** Read the local BYO write-credential config for one vault, or `null` when none is configured on this machine. */ export declare function readByoConfig(keystore: VaultKeystore, repoId: string): VaultByoConfig | null; /** Every repo id with a local BYO write config on this machine. */ export declare function listByoConfiguredRepoIds(keystore: VaultKeystore): string[]; /** Set (create or replace) the local BYO write-credential config for one vault. */ export declare function saveByoConfig(keystore: VaultKeystore, input: { repo_id: string; destination: VaultMirrorDestination; credential?: VaultMirrorCredential; }, now?: () => Date): VaultByoConfig; /** Remove the local BYO write-credential config for one vault. Never touches the customer bucket's own bytes — this only stops THIS machine from writing/reading it as the vault's primary destination. */ export declare function removeByoConfig(keystore: VaultKeystore, repoId: string): { removed: boolean; }; //# sourceMappingURL=vault-byo-config.d.ts.map