Expand description
The ACME server itself: the domain services every front end shares
(acme), the extractors that verify a signed request before a handler
runs (extractors), the handlers (handlers), the layers around them
(middlewares), one endpoint’s identity and subsystems (profile) and
the routers that serve it (router).
Above everything a request consults — the policy, the queue, the signer’s
read side — and below the admin surfaces and the runtime that assembles and
serves it. An internal crate of the acme-proxy binary, published in
lockstep with it and with no semver promise of its own.
Modules§
- acme
- The ACME domain: what an order, an authorization, a challenge and an account may do, independent of the HTTP request that asked.
- extractors
- Request extraction and JWS verification — the security core of the crate.
- handlers
- ACME resource handlers, one module per resource.
- middlewares
- Tower layers, split by what they are allowed to see.
- profile
Profile: one ACME endpoint — its identity, its URLs and the subsystems that answer for it. How a generation builds every one it mounts isserver::profile’s.- router
- The ACME listener’s routers — the whole service and one profile’s — the metrics listener’s, and the response layers shared with the admin listener.