Expand description
Which of the server’s three jobs this process does.
One binary, several processes: acme-proxy serve --role acme,admin,worker,
defaulting to all three. All-in-one stays the default — the split is a
deployment mode, not a replacement, and a serve with no --role builds
exactly what it always did.
What it buys is privilege separation, which is the point for a CA. The
acme role parses untrusted JWS and CSRs from the internet; the admin
role holds operator sessions; the worker role reaches out to
client-chosen hosts, talks to an upstream CA, sends mail, and is the only
one holding the CA key. Each can run under its own uid and sandbox.
This is not sockets::Role, and the two must
not be conflated. That enum names the three listeners a process may hold
(acme, admin, metrics); this one names the three jobs a process may
do. worker holds no socket at all, and metrics is a socket every role
may serve rather than a job anybody does — so the sets differ in both
directions and one type could not carry both meanings.
Structs§
- RoleSet
- The roles one process runs, never empty.
Enums§
- Process
Role - One of the three jobs a process may do.