pub struct AdminConfig {
pub enabled: bool,
pub bind_address: String,
pub base_url: String,
pub session_ttl_seconds: u64,
pub session_idle_timeout_seconds: u64,
pub login_max_attempts: u32,
pub login_window_seconds: u64,
pub require_mfa: bool,
pub max_body_bytes: usize,
pub page_size_max: i64,
pub template_dir: String,
pub tls: AdminTlsConfig,
}Expand description
The web admin interface: a second listener, on its own socket, serving no ACME.
Process-wide, not per-profile – an operator manages every endpoint this
process serves, so there is no [profiles.<name>].admin and this is not in
PROFILE_SECTIONS.
Off by default. A certificate authority should not grow a management surface because somebody upgraded it.
Fields§
§enabled: bool§bind_address: StringLoopback on purpose. This listener has no admission control and no
filter chain, and until AdminTlsConfig::enabled is set, no
transport security either. webadmin::check_config refuses to start on
a non-loopback bind while TLS is off.
base_url: StringThe origin the panel is reached at. Load-bearing three times over: the
CSRF origin check compares against it, a generated self-signed
certificate takes its host, and the pages will build absolute URLs from
it – exactly as server.base_url does for the ACME listener.
session_ttl_seconds: u64Absolute session lifetime. Never extended by activity: past it, the operator signs in again.
session_idle_timeout_seconds: u64Idle session lifetime, advanced on use (at most once a minute, so a polling page is not a stream of database writes).
login_max_attempts: u32Failed logins allowed from one address per window, then 429 with a
Retry-After. The password hash is deliberately expensive, so this is
an availability control as much as a credential one.
login_window_seconds: u64§require_mfa: boolRequire a second factor of every operator.
What this changes is the operator who has none: with it on, their
next sign-in lands on the enrolment page and their session stays
pending_mfa until they finish. An operator who already has a factor is
challenged whether this is set or not – the flag governs enrolment, not
enforcement.
Deliberately not “refuse a password-only login”: enrolling needs a session and a session would then need a factor, so setting this on a panel with no enrolled operator would brick it, with no way in to fix it.
Does not retroactively end sessions that predate it. The lever that does
is acme-proxy admin session revoke --all.
max_body_bytes: usizeLargest admin request body – a small JSON object or a form.
page_size_max: i64Ceiling on ?limit= for the list endpoints.
template_dir: StringOverride individual page templates on disk, mirroring
notify.template_dir. Empty means the compiled-in defaults.
tls: AdminTlsConfigTrait Implementations§
Source§impl Clone for AdminConfig
impl Clone for AdminConfig
Source§fn clone(&self) -> AdminConfig
fn clone(&self) -> AdminConfig
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for AdminConfig
impl Debug for AdminConfig
Source§impl Default for AdminConfig
impl Default for AdminConfig
Source§impl<'de> Deserialize<'de> for AdminConfigwhere
AdminConfig: Default,
impl<'de> Deserialize<'de> for AdminConfigwhere
AdminConfig: Default,
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Auto Trait Implementations§
impl Freeze for AdminConfig
impl RefUnwindSafe for AdminConfig
impl Send for AdminConfig
impl Sync for AdminConfig
impl Unpin for AdminConfig
impl UnsafeUnpin for AdminConfig
impl UnwindSafe for AdminConfig
Blanket Implementations§
Source§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more