pub struct Config {Show 18 fields
pub database: DatabaseConfig,
pub server: ServerConfig,
pub admin: AdminConfig,
pub nonce: NonceConfig,
pub audit: AuditConfig,
pub jobs: JobsConfig,
pub metrics: MetricsConfig,
pub logging: LoggingConfig,
pub order: OrderConfig,
pub signer: SignerConfig,
pub challenge: ChallengeConfig,
pub filter: FilterConfig,
pub ipam: IpamConfig,
pub eab: EabConfig,
pub notify: NotifyConfig,
pub meta: MetaConfig,
pub dns: DnsConfig,
pub proxy: ProxyConfig,
/* private fields */
}Expand description
Runtime configuration for the ACME proxy server.
The eight sections a profile can carry (signer, filter, ipam,
challenge, eab, order, notify, meta) are kept here as the base
every profile inherits; nothing serves them directly. The rest (database, server,
admin, nonce, audit, jobs, metrics, logging, dns, proxy) is process-wide and has no
per-profile form — an operator of the web admin manages every endpoint this process
serves, so admin in particular has no per-profile meaning, audit
records one trail for the whole CA, and jobs drains one queue.
Fields§
§database: DatabaseConfig§server: ServerConfig§admin: AdminConfigThe web admin listener. Process-wide, so deliberately absent from
[PROFILE_SECTIONS].
nonce: NonceConfig§audit: AuditConfigTraceability and the CA’s audit trail. Process-wide for the reason
AuditConfig gives, so also absent from [PROFILE_SECTIONS].
jobs: JobsConfigThe durable background-work queue. Process-wide for the reason
JobsConfig gives, so also absent from [PROFILE_SECTIONS].
metrics: MetricsConfigThe Prometheus exposition endpoint. Process-wide for the reason
MetricsConfig gives, so also absent from [PROFILE_SECTIONS].
logging: LoggingConfig§order: OrderConfig§signer: SignerConfig§challenge: ChallengeConfig§filter: FilterConfig§ipam: IpamConfigThe inventory the ipam filter consults. Per-profile, so two endpoints
may consult different ones — and read by nothing unless that filter is
enabled.
eab: EabConfig§notify: NotifyConfig§meta: MetaConfig§dns: DnsConfig§proxy: ProxyConfigThe forward proxy every outbound client dials through. Process-wide for
the reason ProxyConfig gives, so also absent from
[PROFILE_SECTIONS].
Implementations§
Source§impl Config
impl Config
Sourcepub fn load() -> Result<Self, ConfigError>
pub fn load() -> Result<Self, ConfigError>
Loads configuration from defaults, TOML file, and environment variables.
Sourcepub fn resolve_profiles(&self) -> Result<Vec<ProfileConfig>>
pub fn resolve_profiles(&self) -> Result<Vec<ProfileConfig>>
The profiles this configuration mounts, each fully populated: what the profile states, over what the matching global section states, over the compiled defaults — resolved key by key, not section by section, so a profile changing one knob keeps the rest of the global section.
Fails when nothing is left to serve: profiles are the only way to serve ACME at all, and a server that silently answers nothing would be worse than one that refuses to start.