Block a user
README: threat model, key rotation guide, nginx reverse proxy config
TLS setup (provided cert or ACME)
CLI client (reads VAULT_URL + VAULT_TOKEN env vars)
Export endpoint (.env + JSON formats)
API key middleware (bearer token → bcrypt verify)
REST API server (net/http or chi router)
Master key loading + validation on startup
Encryption layer (AES-256-GCM, envelope encryption)