Skip to main content

Module ops

Module ops 

Source
Expand description

The operator operation layer: what an operator may do to a stored row, independent of which front end asked.

The counterpart of acme_proxy_protocol::acme for the operator surfaces. /api, /ui and the host CLI all reach these functions, so a listing filters the same way, a delete refuses the same way, and a revocation takes the same route whichever one was used. What stays with each front end is its rendering and its authorization.

Two rules hold throughout:

  • A delete that would remove the only record of a live certificate is refused, on every surface, with no override — live_certificates_refusal is the one wording of it.
  • Nothing here builds a signing backend. A revocation is a route (acme_proxy_signer::revocation_route) and, where the key is elsewhere, a queued job — the same path POST /revokeCert takes.

Structs§

Deleted
What a hard delete took with it.
JobDetail
A job plus, when it is a relay issuance, the upstream_orders row it drives — the cross-link the detail view renders as a panel.
OrderDetail
An order plus every authorization (each with its challenges).
UpstreamOrderDetail
An upstream_orders row plus, when one exists, the relay job that drives (or last drove) it — the reverse cross-link.

Enums§

CancelJobError
Why cancel_job failed irrecoverably.
CancelJobOutcome
Outcome of cancel_job / confirm_cancel_job.
ContactError
Why update_account_contact did not write.
DeleteOutcome
Outcome of a confirm-gated hard delete.
Deletion
Outcome of a bare hard delete of something that can hold a certificate — DeleteOutcome without Cancelled, for the reason given there.
EabDeleteOutcome
Outcome of confirm_delete_eab: EabDeletion plus Cancelled.
RevokeError
Why revoke_order failed.
RevokeOutcome
Outcome of revoke_order.
RunJobNowOutcome
Outcome of run_job_now.

Functions§

cancel_job
Cancels a job. For an in-flight signer_relay_issue job this also abandons the ACME order — Order::mark_invalid (generic problem document, so the client stops polling), UpstreamOrder::mark_invalid (so RelayJob::recover does not resurrect it), and one certificate_issue_failed audit row attributed to actor/client. An in-flight signer_issue job does the same to its still-processing order, minus the mapping row it never had.
cleanup_audit
Deletes audit rows older than days, returning how many went.
cleanup_nonces
Runs Nonce::cleanup, returning how many were removed.
confirm_cancel_job
cancel_job with a confirmation prompt. Ok(None) when the operator declined — the confirm_cleanup_* shape.
confirm_cleanup_audit
Confirms, then runs cleanup_audit. None when the operator declined.
confirm_cleanup_nonces
Confirms, then runs cleanup_nonces. None when the operator declined.
confirm_delete_account
Looks up the account, shows what will cascade, confirms, then hard-deletes it.
confirm_delete_eab
delete_eab, asking first and naming what happens to the accounts.
confirm_delete_order
Same shape as confirm_delete_account, for an order.
deactivate_account
Deactivates an account, and queues account_deactivated through its profile’s dispatcher — notifier looks one up by profile name, None where this process has none — naming client_ip as whoever asked.
delete_account
Hard-deletes an account unless it holds a live certificate. Carries how many orders cascaded with it.
delete_eab
Deletes an EAB credential, doing accounts to the accounts it bound. The web admin’s form; the refusal and the transaction live in Eab::delete.
delete_order
Hard-deletes an order unless it holds a live certificate. Carries how many authorizations cascaded with it.
eab_live_certificates_refusal
live_certificates_refusal for eab delete with its accounts, which has a third way out the other two lack.
find_audit
One audit row by id.
is_periodic_job_kind
Whether cancelling a job of this kind silently stops a periodic sweep.
list_audit
One page of audit rows, plus the unpaged total the same filters match.
live_certificates_refusal
What every front end tells an operator whose delete was refused for holding live certificates. One wording, so the CLI, the API and the page cannot describe one refusal three ways.
load_job_detail
Loads a job by id, attaching its upstream_orders row when it is a relay issuance. None for a junk id or an unknown job.
load_order_detail
Loads order detail.
load_upstream_order_detail
Loads an upstream_orders row by its local order id, attaching the most recent relay job for it (live or terminal). None for a junk id or an order no relay was opened for.
orders_json
A page of orders as their admin JSON, each with its authorization ids.
revoke_order
Revokes an order’s issued certificate at the signer backend and records it on the order.
run_job_now
Makes a job eligible to run immediately: a live ready job’s run_at is pulled forward; a failed/exhausted one is revived for exactly one more attempt (attempts set to max_attempts - 1). Refused on running/done/cancelled.
unmounted_profile_refusal
The refusal for an EAB credential scoped to a profile nothing mounts, if it is one — None when the profile is mounted, or when the credential is for every endpoint.
update_account_contact
Updates an account’s contact list, refusing what newAccount would refuse (acme_proxy_protocol::acme::account::update_contact, the one check every surface shares).