Expand description
The command tree, and the startup path itself.
Nothing here prints or exits. Every command body returns
Result<(), CliError> and dispatch routes to it, so each arm is a plain
function a test can call and assert on rather than an unreachable dead end.
src/main.rs is where that Result becomes an exit status, and it is the
only place in the project that calls std::process::exit — a library whose
failure mode is ending the process is one nothing else can use.
Startup is split on the socket boundary, which is what lets a test drive the whole path on an ephemeral port with its own shutdown future instead of a process signal:
servebindsserver.bind_address, installs theSIGHUPhandler, and hands the socket on.serve_onvalidates the admin configuration and binds that socket too, when[admin]is enabled.serve_on_withdoes everything else — profile resolution, deduplicated signer backends, per-profile filters and validators, TLS, the job registry (every signer’s handlers, notification delivery and the four table sweeps), the runner draining it, andaxum::servewith connect info attached.
That assembly is [build_generation], and it is called again on every
reload rather than only at startup — so the two cannot drift, and a
subsystem added to one is added to the other by construction. What a reload
may change, and what it refuses by name, is crate::reload’s to say;
serve_on_with_reloads is where the two meet.
The logic behind each admin subcommand lives in crate::admin, not here;
this module is the clap surface over it. [logging] turns [logging] into
an installed subscriber, validating every value before installing anything.
What a command prints is render’s, and how it is coloured is
style’s. Those renderings sit here rather than in crate::admin
because they have exactly one consumer — the terminal — where the JSON ones
beside them are a wire format the web admin parses too. dispatch
resolves one Palette and threads it down; nonce and upstream take
none, printing only fixed text.
Re-exports§
pub use account::AccountCommand;pub use audit::AuditCommand;pub use eab::EabCommand;pub use nonce::NonceCommand;pub use order::OrderCommand;pub use upstream::UpstreamCommand;pub use webadmin::AdminCommand;pub use crate::cli::style::ColorChoice;pub use crate::cli::style::Palette;
Modules§
- account
- audit
- eab
- filter
acme-proxy filter show|explain— reading the configured access policy.- nonce
- order
- render
- The human-readable renderings, and the only place colour is woven in.
- style
- Colour for the admin CLI’s human-readable output.
- upstream
acme-proxy upstream …— managing this server’s own ACME account at the upstream CA, when therelaysigner backend is in use.- webadmin
acme-proxy admin …— the web admin’s operators and their sessions.
Structs§
Enums§
Functions§
- check_
metrics_ config - Refuses a
[metrics]bind address that collides with another listener’s. - dispatch
- Routes a parsed command to its handler.
- init_
logging - Installs the
[logging]configuration. Re-exported becausemain.rsis what calls it — seedispatch. Installs the process-wide tracing subscriber from[logging]. - serve
- Binds the configured socket and runs the ACME HTTP(S) server until a shutdown signal arrives.
- serve_
on - Assembles and serves the application over an already-bound socket.
- serve_
on_ with serve_onwith all three sockets supplied.- serve_
on_ with_ reloads serve_on_with, serving configuration reloads as well as requests.