Expand description
Persistence: one module per table, over sqlx and SQLite or PostgreSQL —
acme-proxy’s storage layer, below everything that reads or writes a row. An internal
crate of the acme-proxy binary, published in lockstep with it and with no
semver promise of its own.
Queries are built with the runtime sqlx::query API rather than the
compile-time macros, so DATABASE_URL is not needed to build the crate.
Migrations are embedded and run at startup — see db.
Two invariants shape almost everything here:
- A profile is a data boundary.
accountsandorderscarry aprofilecolumn andaccountsis keyedUNIQUE(profile, pubkey), so one client key at two endpoints is two unrelated accounts. Request-path lookups always take the profile; the admin layer uses the deliberately unscopedfind_any_*variants. auditrows outlive their subjects. That table has no foreign keys, because aCASCADEwould delete the evidence along with the account or order it describes. It is INSERT-only: there is no setter and noUPDATEagainst it anywhere in the crate.
Methods return Result<_, sqlx::Error> and leave the mapping to a
acme_proxy_core::error::Problem to their caller.
Modules§
- account
- ACME accounts (RFC 8555 §7.1.2) — the
accountstable. - admin_
recovery_ code - The web admin’s second-factor recovery codes — the
admin_recovery_codestable. - admin_
session - The web admin’s browser sessions — the
admin_sessionstable. - admin_
user - The web admin’s operators — the
admin_userstable — and their privilege tier,AdminRole. - audit
- The
audit_logmodel: append, read back, purge by age. - authz
- ACME authorizations (RFC 8555 §7.1.4) and their challenges (§8) — the
authorizationsandchallengestables. - crl
- The
crlstable: each local CA’s current signed CRL. - db
- The connection, and the only holder of the pool.
- eab
- External Account Binding credentials (RFC 8555 §7.3.4) — the
eab_keystable.Eabdescribes the row and its methods. - expiring
- The expiry list: one query (
Order::find_expiring), one annotator (annotate_expiring) and three consumers — the[notify.expiry]digest, the panel (GET /api/expiringand/ui/expiring) andorder list --expiring-in. The annotation used to live inside the digest’s job type, where the panel could not reach it — two answers to “has this been replaced?” was exactly one too many. - http01_
token - The
http01_tokenstable: key authorizations therelaybackend publishes for its upstream CA to fetch (RFC 8555 §8.3). - id
- Row ids: minting them, and reading one that arrived from outside.
- job
- The
jobsmodel: the durable queue behindjobs. - nonce
- Replay nonces (RFC 8555 §6.5): minted on every response, spent by the next signed request.
- order
- Orders (RFC 8555 §7.1.3), and every query over them.
- query
- The one piece every paged listing in this tree builds its
WHEREfrom. - revocation
- The
revocationstable: what a local CA has revoked. - sql
- The one place either driver is named, and the reason the SQL is written once.
- status
- The three ACME state machines, as types rather than strings.
- transfer
- Copying every row from one backend to the other.
- upstream_
order - The mapping between a local order and the order the
relaysigner backend opened for it at the upstream CA.