Expand description
The web admin interface: a second HTTP listener, serving no ACME.
§Where this sits
src/cli/ and crates/admin/src/webadmin/ are the two front ends; crates/admin/src/admin/ is
the operation layer both dispatch to and neither owns. A handler here is a
few lines over an admin::ops call and an admin::render_*_json, the same
way a src/cli/ command body is a few lines over the same call and a
render_*_line.
§Why a second listener
The ACME listener is public, unauthenticated and often internet-facing.
This one defaults to loopback, requires a session on every route but login,
carries no admission control, and runs its own address policy,
[admin.filter] (see filter), rather than the ACME profiles’ one. Keeping them on one socket would have meant one
set of defaults for two very different threat models.
Re-exports§
pub use error::AdminError;pub use pages::PageError;pub use session::LoginLimiter;
Modules§
- error
- The admin API’s error type.
- filter
[admin.filter]: who may reach the admin listener at all.- handlers
- One module per admin resource, re-exported flat — mirroring
acme_proxy_protocol::handlers, which does the same for the ACME resources. - pages
/ui— the HTML the operator actually looks at.- session
- Session tokens, the cookie they travel in, the extractors that resolve them, the CSRF check, and the login rate limiter.
Structs§
- Admin
State - Shared state for every admin route.
Functions§
- build_
admin_ app - Builds the whole admin service:
/health, then the JSON API under/api. - build_
admin_ app_ with_ logins build_admin_app, carrying login counters across a configuration reload.- catch_
panic_ admin_ api - The last-resort panic layer for the admin
/apinest — see [admin_api_panic_response]. - catch_
panic_ admin_ pages - The last-resort panic layer for the admin pages and the HTML fallback — see
[
admin_page_panic_response].pubon the same terms asbuild_admin_app. - check_
config - Rejects an
[admin]section that cannot work, before anything binds.