Skip to main content

Crate acme_proxy_store

Crate acme_proxy_store 

Source
Expand description

Persistence: one module per table, over sqlx and SQLite or PostgreSQL — acme-proxy’s storage layer, below everything that reads or writes a row. An internal crate of the acme-proxy binary, published in lockstep with it and with no semver promise of its own.

Queries are built with the runtime sqlx::query API rather than the compile-time macros, so DATABASE_URL is not needed to build the crate. Migrations are embedded and run at startup — see db.

Two invariants shape almost everything here:

  • A profile is a data boundary. accounts and orders carry a profile column and accounts is keyed UNIQUE(profile, pubkey), so one client key at two endpoints is two unrelated accounts. Request-path lookups always take the profile; the admin layer uses the deliberately unscoped find_any_* variants.
  • audit rows outlive their subjects. That table has no foreign keys, because a CASCADE would delete the evidence along with the account or order it describes. It is INSERT-only: there is no setter and no UPDATE against it anywhere in the crate.

Methods return Result<_, sqlx::Error> and leave the mapping to a acme_proxy_core::error::Problem to their caller.

Modules§

account
ACME accounts (RFC 8555 §7.1.2) — the accounts table.
admin_recovery_code
The web admin’s second-factor recovery codes — the admin_recovery_codes table.
admin_session
The web admin’s browser sessions — the admin_sessions table.
admin_user
The web admin’s operators — the admin_users table — and their privilege tier, AdminRole.
audit
The audit_log model: append, read back, purge by age.
authz
ACME authorizations (RFC 8555 §7.1.4) and their challenges (§8) — the authorizations and challenges tables.
crl
The crls table: each local CA’s current signed CRL.
db
The connection, and the only holder of the pool.
eab
External Account Binding credentials (RFC 8555 §7.3.4) — the eab_keys table. Eab describes the row and its methods.
expiring
The expiry list: one query (Order::find_expiring), one annotator (annotate_expiring) and three consumers — the [notify.expiry] digest, the panel (GET /api/expiring and /ui/expiring) and order list --expiring-in. The annotation used to live inside the digest’s job type, where the panel could not reach it — two answers to “has this been replaced?” was exactly one too many.
http01_token
The http01_tokens table: key authorizations the relay backend publishes for its upstream CA to fetch (RFC 8555 §8.3).
id
Row ids: minting them, and reading one that arrived from outside.
job
The jobs model: the durable queue behind jobs.
nonce
Replay nonces (RFC 8555 §6.5): minted on every response, spent by the next signed request.
order
Orders (RFC 8555 §7.1.3), and every query over them.
query
The one piece every paged listing in this tree builds its WHERE from.
revocation
The revocations table: what a local CA has revoked.
sql
The one place either driver is named, and the reason the SQL is written once.
status
The three ACME state machines, as types rather than strings.
transfer
Copying every row from one backend to the other.
upstream_order
The mapping between a local order and the order the relay signer backend opened for it at the upstream CA.