Expand description
The operator operation layer: what an operator may do to a stored row, independent of which front end asked.
The counterpart of acme_proxy_protocol::acme for the operator surfaces.
/api, /ui and the host CLI all reach these functions, so a listing
filters the same way, a delete refuses the same way, and a revocation takes
the same route whichever one was used. What stays with each front end is its
rendering and its authorization.
Two rules hold throughout:
- A delete that would remove the only record of a live certificate is
refused, on every surface, with no override —
live_certificates_refusalis the one wording of it. - Nothing here builds a signing backend. A revocation is a route
(
acme_proxy_signer::revocation_route) and, where the key is elsewhere, a queued job — the same pathPOST /revokeCerttakes.
Structs§
- Deleted
- What a hard delete took with it.
- JobDetail
- A job plus, when it is a relay issuance, the
upstream_ordersrow it drives — the cross-link the detail view renders as a panel. - Order
Detail - An order plus every authorization (each with its challenges).
- Upstream
Order Detail - An
upstream_ordersrow plus, when one exists, the relay job that drives (or last drove) it — the reverse cross-link.
Enums§
- Cancel
JobError - Why
cancel_jobfailed irrecoverably. - Cancel
JobOutcome - Outcome of
cancel_job/confirm_cancel_job. - Contact
Error - Why
update_account_contactdid not write. - Delete
Outcome - Outcome of a confirm-gated hard delete.
- Deletion
- Outcome of a bare hard delete of something that can hold a certificate —
DeleteOutcomewithoutCancelled, for the reason given there. - EabDelete
Outcome - Outcome of
confirm_delete_eab:EabDeletionplusCancelled. - Revoke
Error - Why
revoke_orderfailed. - Revoke
Outcome - Outcome of
revoke_order. - RunJob
NowOutcome - Outcome of
run_job_now.
Functions§
- cancel_
job - Cancels a job. For an in-flight
signer_relay_issuejob this also abandons the ACME order —Order::mark_invalid(generic problem document, so the client stops polling),UpstreamOrder::mark_invalid(soRelayJob::recoverdoes not resurrect it), and onecertificate_issue_failedaudit row attributed toactor/client. An in-flightsigner_issuejob does the same to its still-processingorder, minus the mapping row it never had. - cleanup_
audit - Deletes audit rows older than
days, returning how many went. - cleanup_
nonces - Runs
Nonce::cleanup, returning how many were removed. - confirm_
cancel_ job cancel_jobwith a confirmation prompt.Ok(None)when the operator declined — theconfirm_cleanup_*shape.- confirm_
cleanup_ audit - Confirms, then runs
cleanup_audit.Nonewhen the operator declined. - confirm_
cleanup_ nonces - Confirms, then runs
cleanup_nonces.Nonewhen the operator declined. - confirm_
delete_ account - Looks up the account, shows what will cascade, confirms, then hard-deletes it.
- confirm_
delete_ eab delete_eab, asking first and naming what happens to the accounts.- confirm_
delete_ order - Same shape as
confirm_delete_account, for an order. - deactivate_
account - Deactivates an account, and queues
account_deactivatedthrough its profile’s dispatcher —notifierlooks one up by profile name,Nonewhere this process has none — namingclient_ipas whoever asked. - delete_
account - Hard-deletes an account unless it holds a live certificate. Carries how many orders cascaded with it.
- delete_
eab - Deletes an EAB credential, doing
accountsto the accounts it bound. The web admin’s form; the refusal and the transaction live inEab::delete. - delete_
order - Hard-deletes an order unless it holds a live certificate. Carries how many authorizations cascaded with it.
- eab_
live_ certificates_ refusal live_certificates_refusalforeab deletewith its accounts, which has a third way out the other two lack.- find_
audit - One audit row by id.
- is_
periodic_ job_ kind - Whether cancelling a job of this kind silently stops a periodic sweep.
- list_
audit - One page of audit rows, plus the unpaged total the same filters match.
- live_
certificates_ refusal - What every front end tells an operator whose delete was refused for holding live certificates. One wording, so the CLI, the API and the page cannot describe one refusal three ways.
- load_
job_ detail - Loads a job by id, attaching its
upstream_ordersrow when it is a relay issuance.Nonefor a junk id or an unknown job. - load_
order_ detail - Loads order detail.
- load_
upstream_ order_ detail - Loads an
upstream_ordersrow by its local order id, attaching the most recent relay job for it (live or terminal).Nonefor a junk id or an order no relay was opened for. - orders_
json - A page of orders as their admin JSON, each with its authorization ids.
- revoke_
order - Revokes an order’s issued certificate at the signer backend and records it on the order.
- run_
job_ now - Makes a job eligible to run immediately: a live
readyjob’srun_atis pulled forward; afailed/exhausted one is revived for exactly one more attempt (attemptsset tomax_attempts - 1). Refused onrunning/done/cancelled. - unmounted_
profile_ refusal - The refusal for an EAB credential scoped to a profile nothing mounts, if it
is one —
Nonewhen the profile is mounted, or when the credential is for every endpoint. - update_
account_ contact - Updates an account’s contact list, refusing what
newAccountwould refuse (acme_proxy_protocol::acme::account::update_contact, the one check every surface shares).